FIPS Product: YES FIPS Kernel: NO FIPS Mode: NO NSS DB directory: sql:/etc/ipsec.d Initializing NSS Opening NSS database "sql:/etc/ipsec.d" read-only NSS initialized NSS crypto library initialized FIPS HMAC integrity support [enabled] FIPS mode disabled for pluto daemon FIPS HMAC integrity verification self-test FAILED libcap-ng support [enabled] Linux audit support [enabled] Linux audit activated Starting Pluto (Libreswan Version v3.28-685-gbfd5aef521-master-s2 XFRM(netkey) esp-hw-offload FORK PTHREAD_SETSCHEDPRIO NSS (IPsec profile) DNSSEC FIPS_CHECK LABELED_IPSEC SECCOMP LIBCAP_NG LINUX_AUDIT XAUTH_PAM NETWORKMANAGER CURL(non-NSS)) pid:17917 core dump dir: /run/pluto secrets file: /etc/ipsec.secrets leak-detective enabled NSS crypto [enabled] XAUTH PAM support [enabled] | libevent is using pluto's memory allocator Initializing libevent in pthreads mode: headers: 2.1.8-stable (2010800); library: 2.1.8-stable (2010800) | libevent_malloc: new ptr-libevent@0x56546b7ba6b8 size 40 | libevent_malloc: new ptr-libevent@0x56546b7ba638 size 40 | libevent_malloc: new ptr-libevent@0x56546b7ba5b8 size 40 | creating event base | libevent_malloc: new ptr-libevent@0x56546b7ba938 size 56 | libevent_malloc: new ptr-libevent@0x56546b72d3a8 size 664 | libevent_malloc: new ptr-libevent@0x56546b7f4cd8 size 24 | libevent_malloc: new ptr-libevent@0x56546b7f4d28 size 384 | libevent_malloc: new ptr-libevent@0x56546b7f4c98 size 16 | libevent_malloc: new ptr-libevent@0x56546b7ba538 size 40 | libevent_malloc: new ptr-libevent@0x56546b7ba4b8 size 48 | libevent_realloc: new ptr-libevent@0x56546b72d038 size 256 | libevent_malloc: new ptr-libevent@0x56546b7f4ed8 size 16 | libevent_free: release ptr-libevent@0x56546b7ba938 | libevent initialized | libevent_realloc: new ptr-libevent@0x56546b7ba938 size 64 | global periodic timer EVENT_RESET_LOG_RATE_LIMIT enabled with interval of 3600 seconds | init_nat_traversal() initialized with keep_alive=0s NAT-Traversal support [enabled] | global one-shot timer EVENT_NAT_T_KEEPALIVE initialized | global one-shot timer EVENT_FREE_ROOT_CERTS initialized | global periodic timer EVENT_REINIT_SECRET enabled with interval of 3600 seconds | global one-shot timer EVENT_REVIVE_CONNS initialized | global periodic timer EVENT_PENDING_DDNS enabled with interval of 60 seconds | global periodic timer EVENT_PENDING_PHASE2 enabled with interval of 120 seconds Encryption algorithms: AES_CCM_16 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm, aes_ccm_c AES_CCM_12 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_b AES_CCM_8 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_a 3DES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS [*192] 3des CAMELLIA_CTR IKEv1: ESP IKEv2: ESP {256,192,*128} CAMELLIA_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} camellia AES_GCM_16 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm, aes_gcm_c AES_GCM_12 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_b AES_GCM_8 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_a AES_CTR IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aesctr AES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aes SERPENT_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} serpent TWOFISH_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} twofish TWOFISH_SSH IKEv1: IKE IKEv2: IKE ESP {256,192,*128} twofish_cbc_ssh NULL_AUTH_AES_GMAC IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_gmac NULL IKEv1: ESP IKEv2: ESP [] CHACHA20_POLY1305 IKEv1: IKEv2: IKE ESP [*256] chacha20poly1305 Hash algorithms: MD5 IKEv1: IKE IKEv2: SHA1 IKEv1: IKE IKEv2: FIPS sha SHA2_256 IKEv1: IKE IKEv2: FIPS sha2, sha256 SHA2_384 IKEv1: IKE IKEv2: FIPS sha384 SHA2_512 IKEv1: IKE IKEv2: FIPS sha512 PRF algorithms: HMAC_MD5 IKEv1: IKE IKEv2: IKE md5 HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS sha, sha1 HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS sha2, sha256, sha2_256 HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS sha384, sha2_384 HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS sha512, sha2_512 AES_XCBC IKEv1: IKEv2: IKE aes128_xcbc Integrity algorithms: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH md5, hmac_md5 HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha, sha1, sha1_96, hmac_sha1 HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha512, sha2_512, sha2_512_256, hmac_sha2_512 HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha384, sha2_384, sha2_384_192, hmac_sha2_384 HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH aes_xcbc, aes128_xcbc, aes128_xcbc_96 AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac NONE IKEv1: ESP IKEv2: IKE ESP FIPS null DH algorithms: NONE IKEv1: IKEv2: IKE ESP AH FIPS null, dh0 MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH dh5 MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh14 MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh15 MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh16 MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh17 MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh18 DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_256, ecp256 DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_384, ecp384 DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_521, ecp521 DH31 IKEv1: IKE IKEv2: IKE ESP AH curve25519 testing CAMELLIA_CBC: Camellia: 16 bytes with 128-bit key Camellia: 16 bytes with 128-bit key Camellia: 16 bytes with 256-bit key Camellia: 16 bytes with 256-bit key testing AES_GCM_16: empty string one block two blocks two blocks with associated data testing AES_CTR: Encrypting 16 octets using AES-CTR with 128-bit key Encrypting 32 octets using AES-CTR with 128-bit key Encrypting 36 octets using AES-CTR with 128-bit key Encrypting 16 octets using AES-CTR with 192-bit key Encrypting 32 octets using AES-CTR with 192-bit key Encrypting 36 octets using AES-CTR with 192-bit key Encrypting 16 octets using AES-CTR with 256-bit key Encrypting 32 octets using AES-CTR with 256-bit key Encrypting 36 octets using AES-CTR with 256-bit key testing AES_CBC: Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key testing AES_XCBC: RFC 3566 Test Case #1: AES-XCBC-MAC-96 with 0-byte input RFC 3566 Test Case #2: AES-XCBC-MAC-96 with 3-byte input RFC 3566 Test Case #3: AES-XCBC-MAC-96 with 16-byte input RFC 3566 Test Case #4: AES-XCBC-MAC-96 with 20-byte input RFC 3566 Test Case #5: AES-XCBC-MAC-96 with 32-byte input RFC 3566 Test Case #6: AES-XCBC-MAC-96 with 34-byte input RFC 3566 Test Case #7: AES-XCBC-MAC-96 with 1000-byte input RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) testing HMAC_MD5: RFC 2104: MD5_HMAC test 1 RFC 2104: MD5_HMAC test 2 RFC 2104: MD5_HMAC test 3 8 CPU cores online starting up 7 crypto helpers started thread for crypto helper 0 started thread for crypto helper 1 | starting up helper thread 0 started thread for crypto helper 2 | status value returned by setting the priority of this thread (crypto helper 0) 22 | starting up helper thread 1 | status value returned by setting the priority of this thread (crypto helper 1) 22 started thread for crypto helper 3 | starting up helper thread 2 | status value returned by setting the priority of this thread (crypto helper 2) 22 started thread for crypto helper 4 started thread for crypto helper 5 started thread for crypto helper 6 | checking IKEv1 state table | starting up helper thread 6 | crypto helper 0 waiting (nothing to do) | starting up helper thread 3 | starting up helper thread 5 | crypto helper 1 waiting (nothing to do) | starting up helper thread 4 | status value returned by setting the priority of this thread (crypto helper 3) 22 | crypto helper 3 waiting (nothing to do) | status value returned by setting the priority of this thread (crypto helper 6) 22 | crypto helper 6 waiting (nothing to do) | MAIN_R0: category: half-open IKE SA flags: 0: | -> MAIN_R1 EVENT_SO_DISCARD | MAIN_I1: category: half-open IKE SA flags: 0: | -> MAIN_I2 EVENT_RETRANSMIT | MAIN_R1: category: open IKE SA flags: 200: | -> MAIN_R2 EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | status value returned by setting the priority of this thread (crypto helper 5) 22 | crypto helper 2 waiting (nothing to do) | MAIN_I2: category: open IKE SA flags: 0: | -> MAIN_I3 EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | MAIN_R2: category: open IKE SA flags: 0: | -> MAIN_R3 EVENT_SA_REPLACE | -> MAIN_R3 EVENT_SA_REPLACE | -> UNDEFINED EVENT_SA_REPLACE | MAIN_I3: category: open IKE SA flags: 0: | -> MAIN_I4 EVENT_SA_REPLACE | -> MAIN_I4 EVENT_SA_REPLACE | -> UNDEFINED EVENT_SA_REPLACE | MAIN_R3: category: established IKE SA flags: 200: | -> UNDEFINED EVENT_NULL | MAIN_I4: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | AGGR_R0: category: half-open IKE SA flags: 0: | status value returned by setting the priority of this thread (crypto helper 4) 22 | -> AGGR_R1 EVENT_SO_DISCARD | AGGR_I1: category: half-open IKE SA flags: 0: | -> AGGR_I2 EVENT_SA_REPLACE | -> AGGR_I2 EVENT_SA_REPLACE | AGGR_R1: category: open IKE SA flags: 200: | -> AGGR_R2 EVENT_SA_REPLACE | -> AGGR_R2 EVENT_SA_REPLACE | AGGR_I2: category: established IKE SA flags: 200: | -> UNDEFINED EVENT_NULL | AGGR_R2: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | QUICK_R0: category: established CHILD SA flags: 0: | -> QUICK_R1 EVENT_RETRANSMIT | QUICK_I1: category: established CHILD SA flags: 0: | -> QUICK_I2 EVENT_SA_REPLACE | QUICK_R1: category: established CHILD SA flags: 0: | -> QUICK_R2 EVENT_SA_REPLACE | QUICK_I2: category: established CHILD SA flags: 200: | -> UNDEFINED EVENT_NULL | QUICK_R2: category: established CHILD SA flags: 0: | -> UNDEFINED EVENT_NULL | INFO: category: informational flags: 0: | -> UNDEFINED EVENT_NULL | INFO_PROTECTED: category: informational flags: 0: | -> UNDEFINED EVENT_NULL | XAUTH_R0: category: established IKE SA flags: 0: | -> XAUTH_R1 EVENT_NULL | crypto helper 5 waiting (nothing to do) | crypto helper 4 waiting (nothing to do) | XAUTH_R1: category: established IKE SA flags: 0: | -> MAIN_R3 EVENT_SA_REPLACE | MODE_CFG_R0: category: informational flags: 0: | -> MODE_CFG_R1 EVENT_SA_REPLACE | MODE_CFG_R1: category: established IKE SA flags: 0: | -> MODE_CFG_R2 EVENT_SA_REPLACE | MODE_CFG_R2: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | MODE_CFG_I1: category: established IKE SA flags: 0: | -> MAIN_I4 EVENT_SA_REPLACE | XAUTH_I0: category: established IKE SA flags: 0: | -> XAUTH_I1 EVENT_RETRANSMIT | XAUTH_I1: category: established IKE SA flags: 0: | -> MAIN_I4 EVENT_RETRANSMIT | checking IKEv2 state table | PARENT_I0: category: ignore flags: 0: | -> PARENT_I1 EVENT_RETRANSMIT send-request (initiate IKE_SA_INIT) | PARENT_I1: category: half-open IKE SA flags: 0: | -> PARENT_I1 EVENT_RETAIN send-request (Initiator: process SA_INIT reply notification) | -> PARENT_I2 EVENT_RETRANSMIT send-request (Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH) | PARENT_I2: category: open IKE SA flags: 0: | -> PARENT_I2 EVENT_NULL (Initiator: process INVALID_SYNTAX AUTH notification) | -> PARENT_I2 EVENT_NULL (Initiator: process AUTHENTICATION_FAILED AUTH notification) | -> PARENT_I2 EVENT_NULL (Initiator: process UNSUPPORTED_CRITICAL_PAYLOAD AUTH notification) | -> V2_IPSEC_I EVENT_SA_REPLACE (Initiator: process IKE_AUTH response) | -> PARENT_I2 EVENT_NULL (IKE SA: process IKE_AUTH response containing unknown notification) | PARENT_I3: category: established IKE SA flags: 0: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Request) | -> PARENT_I3 EVENT_RETAIN (I3: Informational Response) | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Request) | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Response) | PARENT_R0: category: half-open IKE SA flags: 0: | -> PARENT_R1 EVENT_SO_DISCARD send-request (Respond to IKE_SA_INIT) | PARENT_R1: category: half-open IKE SA flags: 0: | -> PARENT_R1 EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request (no SKEYSEED)) | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request) | PARENT_R2: category: established IKE SA flags: 0: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Request) | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Response) | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Request) | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Response) | V2_CREATE_I0: category: established IKE SA flags: 0: | -> V2_CREATE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec SA) | V2_CREATE_I: category: established IKE SA flags: 0: | -> V2_IPSEC_I EVENT_SA_REPLACE (Process CREATE_CHILD_SA IPsec SA Response) | V2_REKEY_IKE_I0: category: established IKE SA flags: 0: | -> V2_REKEY_IKE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IKE Rekey) | V2_REKEY_IKE_I: category: established IKE SA flags: 0: | -> PARENT_I3 EVENT_SA_REPLACE (Process CREATE_CHILD_SA IKE Rekey Response) | V2_REKEY_CHILD_I0: category: established IKE SA flags: 0: | -> V2_REKEY_CHILD_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec Rekey SA) | V2_REKEY_CHILD_I: category: established IKE SA flags: 0: | V2_CREATE_R: category: established IKE SA flags: 0: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IPsec SA Request) | V2_REKEY_IKE_R: category: established IKE SA flags: 0: | -> PARENT_R2 EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IKE Rekey) | V2_REKEY_CHILD_R: category: established IKE SA flags: 0: | V2_IPSEC_I: category: established CHILD SA flags: 0: | V2_IPSEC_R: category: established CHILD SA flags: 0: | IKESA_DEL: category: established IKE SA flags: 0: | -> IKESA_DEL EVENT_RETAIN (IKE_SA_DEL: process INFORMATIONAL) | CHILDSA_DEL: category: informational flags: 0: Using Linux XFRM/NETKEY IPsec interface code on 5.1.18-200.fc29.x86_64 | Hard-wiring algorithms | adding AES_CCM_16 to kernel algorithm db | adding AES_CCM_12 to kernel algorithm db | adding AES_CCM_8 to kernel algorithm db | adding 3DES_CBC to kernel algorithm db | adding CAMELLIA_CBC to kernel algorithm db | adding AES_GCM_16 to kernel algorithm db | adding AES_GCM_12 to kernel algorithm db | adding AES_GCM_8 to kernel algorithm db | adding AES_CTR to kernel algorithm db | adding AES_CBC to kernel algorithm db | adding SERPENT_CBC to kernel algorithm db | adding TWOFISH_CBC to kernel algorithm db | adding NULL_AUTH_AES_GMAC to kernel algorithm db | adding NULL to kernel algorithm db | adding CHACHA20_POLY1305 to kernel algorithm db | adding HMAC_MD5_96 to kernel algorithm db | adding HMAC_SHA1_96 to kernel algorithm db | adding HMAC_SHA2_512_256 to kernel algorithm db | adding HMAC_SHA2_384_192 to kernel algorithm db | adding HMAC_SHA2_256_128 to kernel algorithm db | adding HMAC_SHA2_256_TRUNCBUG to kernel algorithm db | adding AES_XCBC_96 to kernel algorithm db | adding AES_CMAC_96 to kernel algorithm db | adding NONE to kernel algorithm db | net.ipv6.conf.all.disable_ipv6=1 ignore ipv6 holes | global periodic timer EVENT_SHUNT_SCAN enabled with interval of 20 seconds | setup kernel fd callback | add_fd_read_event_handler: new KERNEL_XRM_FD-pe@0x56546b7b43e8 | libevent_malloc: new ptr-libevent@0x56546b7f3468 size 128 | libevent_malloc: new ptr-libevent@0x56546b7fa4d8 size 16 | add_fd_read_event_handler: new KERNEL_ROUTE_FD-pe@0x56546b7fa468 | libevent_malloc: new ptr-libevent@0x56546b7acc88 size 128 | libevent_malloc: new ptr-libevent@0x56546b7fa138 size 16 | global one-shot timer EVENT_CHECK_CRLS initialized selinux support is enabled. | unbound context created - setting debug level to 5 | /etc/hosts lookups activated | /etc/resolv.conf usage activated | outgoing-port-avoid set 0-65535 | outgoing-port-permit set 32768-60999 | Loading dnssec root key from:/var/lib/unbound/root.key | No additional dnssec trust anchors defined via dnssec-trusted= option | Setting up events, loop start | add_fd_read_event_handler: new PLUTO_CTL_FD-pe@0x56546b7fa908 | libevent_malloc: new ptr-libevent@0x56546b806768 size 128 | libevent_malloc: new ptr-libevent@0x56546b811a58 size 16 | libevent_realloc: new ptr-libevent@0x56546b811a98 size 256 | libevent_malloc: new ptr-libevent@0x56546b811bc8 size 8 | libevent_realloc: new ptr-libevent@0x56546b811c08 size 144 | libevent_malloc: new ptr-libevent@0x56546b7b89a8 size 152 | libevent_malloc: new ptr-libevent@0x56546b811cc8 size 16 | signal event handler PLUTO_SIGCHLD installed | libevent_malloc: new ptr-libevent@0x56546b811d08 size 8 | libevent_malloc: new ptr-libevent@0x56546b72df08 size 152 | signal event handler PLUTO_SIGTERM installed | libevent_malloc: new ptr-libevent@0x56546b811d48 size 8 | libevent_malloc: new ptr-libevent@0x56546b726618 size 152 | signal event handler PLUTO_SIGHUP installed | libevent_malloc: new ptr-libevent@0x56546b811d88 size 8 | libevent_realloc: release ptr-libevent@0x56546b811c08 | libevent_realloc: new ptr-libevent@0x56546b811dc8 size 256 | libevent_malloc: new ptr-libevent@0x56546b7266e8 size 152 | signal event handler PLUTO_SIGSYS installed | created addconn helper (pid:17951) using fork+execve | forked child 17951 | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) listening for IKE messages | Inspecting interface lo | found lo with address 127.0.0.1 | Inspecting interface eth0 | found eth0 with address 192.0.2.254 | Inspecting interface eth0:1 | found eth0:1 with address 192.0.2.244 | Inspecting interface eth0:2 | found eth0:2 with address 192.0.2.234 | Inspecting interface eth1 | found eth1 with address 192.1.2.23 Kernel supports NIC esp-hw-offload adding interface eth1/eth1 (esp-hw-offload not supported by kernel) 192.1.2.23:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth1/eth1 192.1.2.23:4500 adding interface eth0:2/eth0:2 (esp-hw-offload not supported by kernel) 192.0.2.234:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth0:2/eth0:2 192.0.2.234:4500 adding interface eth0:1/eth0:1 (esp-hw-offload not supported by kernel) 192.0.2.244:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth0:1/eth0:1 192.0.2.244:4500 adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.2.254:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth0/eth0 192.0.2.254:4500 adding interface lo/lo (esp-hw-offload not supported by kernel) 127.0.0.1:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface lo/lo 127.0.0.1:4500 | no interfaces to sort | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | add_fd_read_event_handler: new ethX-pe@0x56546b812648 | libevent_malloc: new ptr-libevent@0x56546b8066b8 size 128 | libevent_malloc: new ptr-libevent@0x56546b8126b8 size 16 | setup callback for interface lo 127.0.0.1:4500 fd 26 | add_fd_read_event_handler: new ethX-pe@0x56546b8126f8 | libevent_malloc: new ptr-libevent@0x56546b7acd38 size 128 | libevent_malloc: new ptr-libevent@0x56546b812768 size 16 | setup callback for interface lo 127.0.0.1:500 fd 25 | add_fd_read_event_handler: new ethX-pe@0x56546b8127a8 | libevent_malloc: new ptr-libevent@0x56546b7ac688 size 128 | libevent_malloc: new ptr-libevent@0x56546b812818 size 16 | setup callback for interface eth0 192.0.2.254:4500 fd 24 | add_fd_read_event_handler: new ethX-pe@0x56546b812858 | libevent_malloc: new ptr-libevent@0x56546b7abf58 size 128 | libevent_malloc: new ptr-libevent@0x56546b8128c8 size 16 | setup callback for interface eth0 192.0.2.254:500 fd 23 | add_fd_read_event_handler: new ethX-pe@0x56546b812908 | libevent_malloc: new ptr-libevent@0x56546b7ac058 size 128 | libevent_malloc: new ptr-libevent@0x56546b812f38 size 16 | setup callback for interface eth0:1 192.0.2.244:4500 fd 22 | add_fd_read_event_handler: new ethX-pe@0x56546b812f78 | libevent_malloc: new ptr-libevent@0x56546b7ac108 size 128 | libevent_malloc: new ptr-libevent@0x56546b812fe8 size 16 | setup callback for interface eth0:1 192.0.2.244:500 fd 21 | add_fd_read_event_handler: new ethX-pe@0x56546b813028 | libevent_malloc: new ptr-libevent@0x56546b813098 size 128 | libevent_malloc: new ptr-libevent@0x56546b813148 size 16 | setup callback for interface eth0:2 192.0.2.234:4500 fd 20 | add_fd_read_event_handler: new ethX-pe@0x56546b813188 | libevent_malloc: new ptr-libevent@0x56546b8131f8 size 128 | libevent_malloc: new ptr-libevent@0x56546b8132a8 size 16 | setup callback for interface eth0:2 192.0.2.234:500 fd 19 | add_fd_read_event_handler: new ethX-pe@0x56546b8132e8 | libevent_malloc: new ptr-libevent@0x56546b813358 size 128 | libevent_malloc: new ptr-libevent@0x56546b813408 size 16 | setup callback for interface eth1 192.1.2.23:4500 fd 18 | add_fd_read_event_handler: new ethX-pe@0x56546b813448 | libevent_malloc: new ptr-libevent@0x56546b8134b8 size 128 | libevent_malloc: new ptr-libevent@0x56546b813568 size 16 | setup callback for interface eth1 192.1.2.23:500 fd 17 | certs and keys locked by 'free_preshared_secrets' | certs and keys unlocked by 'free_preshared_secrets' loading secrets from "/etc/ipsec.secrets" | saving Modulus | saving PublicExponent | ignoring PrivateExponent | ignoring Prime1 | ignoring Prime2 | ignoring Exponent1 | ignoring Exponent2 | ignoring Coefficient | ignoring CKAIDNSS | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 | computed rsa CKAID 8a 82 25 f1 loaded private key for keyid: PKK_RSA:AQO9bJbr3 | certs and keys locked by 'process_secret' | certs and keys unlocked by 'process_secret' | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.635 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) listening for IKE messages | Inspecting interface lo | found lo with address 127.0.0.1 | Inspecting interface eth0 | found eth0 with address 192.0.2.254 | Inspecting interface eth0:1 | found eth0:1 with address 192.0.2.244 | Inspecting interface eth0:2 | found eth0:2 with address 192.0.2.234 | Inspecting interface eth1 | found eth1 with address 192.1.2.23 | no interfaces to sort | libevent_free: release ptr-libevent@0x56546b8066b8 | free_event_entry: release EVENT_NULL-pe@0x56546b812648 | add_fd_read_event_handler: new ethX-pe@0x56546b812648 | libevent_malloc: new ptr-libevent@0x56546b8066b8 size 128 | setup callback for interface lo 127.0.0.1:4500 fd 26 | libevent_free: release ptr-libevent@0x56546b7acd38 | free_event_entry: release EVENT_NULL-pe@0x56546b8126f8 | add_fd_read_event_handler: new ethX-pe@0x56546b8126f8 | libevent_malloc: new ptr-libevent@0x56546b7acd38 size 128 | setup callback for interface lo 127.0.0.1:500 fd 25 | libevent_free: release ptr-libevent@0x56546b7ac688 | free_event_entry: release EVENT_NULL-pe@0x56546b8127a8 | add_fd_read_event_handler: new ethX-pe@0x56546b8127a8 | libevent_malloc: new ptr-libevent@0x56546b7ac688 size 128 | setup callback for interface eth0 192.0.2.254:4500 fd 24 | libevent_free: release ptr-libevent@0x56546b7abf58 | free_event_entry: release EVENT_NULL-pe@0x56546b812858 | add_fd_read_event_handler: new ethX-pe@0x56546b812858 | libevent_malloc: new ptr-libevent@0x56546b7abf58 size 128 | setup callback for interface eth0 192.0.2.254:500 fd 23 | libevent_free: release ptr-libevent@0x56546b7ac058 | free_event_entry: release EVENT_NULL-pe@0x56546b812908 | add_fd_read_event_handler: new ethX-pe@0x56546b812908 | libevent_malloc: new ptr-libevent@0x56546b7ac058 size 128 | setup callback for interface eth0:1 192.0.2.244:4500 fd 22 | libevent_free: release ptr-libevent@0x56546b7ac108 | free_event_entry: release EVENT_NULL-pe@0x56546b812f78 | add_fd_read_event_handler: new ethX-pe@0x56546b812f78 | libevent_malloc: new ptr-libevent@0x56546b7ac108 size 128 | setup callback for interface eth0:1 192.0.2.244:500 fd 21 | libevent_free: release ptr-libevent@0x56546b813098 | free_event_entry: release EVENT_NULL-pe@0x56546b813028 | add_fd_read_event_handler: new ethX-pe@0x56546b813028 | libevent_malloc: new ptr-libevent@0x56546b813098 size 128 | setup callback for interface eth0:2 192.0.2.234:4500 fd 20 | libevent_free: release ptr-libevent@0x56546b8131f8 | free_event_entry: release EVENT_NULL-pe@0x56546b813188 | add_fd_read_event_handler: new ethX-pe@0x56546b813188 | libevent_malloc: new ptr-libevent@0x56546b8131f8 size 128 | setup callback for interface eth0:2 192.0.2.234:500 fd 19 | libevent_free: release ptr-libevent@0x56546b813358 | free_event_entry: release EVENT_NULL-pe@0x56546b8132e8 | add_fd_read_event_handler: new ethX-pe@0x56546b8132e8 | libevent_malloc: new ptr-libevent@0x56546b813358 size 128 | setup callback for interface eth1 192.1.2.23:4500 fd 18 | libevent_free: release ptr-libevent@0x56546b8134b8 | free_event_entry: release EVENT_NULL-pe@0x56546b813448 | add_fd_read_event_handler: new ethX-pe@0x56546b813448 | libevent_malloc: new ptr-libevent@0x56546b8134b8 size 128 | setup callback for interface eth1 192.1.2.23:500 fd 17 | certs and keys locked by 'free_preshared_secrets' forgetting secrets | certs and keys unlocked by 'free_preshared_secrets' loading secrets from "/etc/ipsec.secrets" | saving Modulus | saving PublicExponent | ignoring PrivateExponent | ignoring Prime1 | ignoring Prime2 | ignoring Exponent1 | ignoring Exponent2 | ignoring Coefficient | ignoring CKAIDNSS | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 | computed rsa CKAID 8a 82 25 f1 loaded private key for keyid: PKK_RSA:AQO9bJbr3 | certs and keys locked by 'process_secret' | certs and keys unlocked by 'process_secret' | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.268 milliseconds in whack | processing signal PLUTO_SIGCHLD | waitpid returned pid 17951 (exited with status 0) | reaped addconn helper child (status 0) | waitpid returned ECHILD (no child processes left) | spent 0.0115 milliseconds in signal handler PLUTO_SIGCHLD | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | Added new connection TUNNEL-A with policy ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | No AUTH policy was set - defaulting to RSASIG | ASCII to DN <= "C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org" | ASCII to DN => 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | ASCII to DN => 31 10 30 0e 06 03 55 04 08 13 07 4f 6e 74 61 72 | ASCII to DN => 69 6f 31 10 30 0e 06 03 55 04 07 13 07 54 6f 72 | ASCII to DN => 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 13 09 4c | ASCII to DN => 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | ASCII to DN => 0b 13 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | ASCII to DN => 6e 74 31 23 30 21 06 03 55 04 03 13 1a 77 65 73 | ASCII to DN => 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | ASCII to DN => 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 65 73 | ASCII to DN => 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org is 0 | setting ID to ID_DER_ASN1_DN: 'E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' | loading right certificate 'east' pubkey | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b818118 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b8180c8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b817f88 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b8174c8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b817478 | unreference key: 0x56546b818168 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | certs and keys locked by 'lsw_add_rsa_secret' | certs and keys unlocked by 'lsw_add_rsa_secret' | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org is 0 | connect_to_host_pair: 192.1.2.23:500 192.1.2.45:500 -> hp@(nil): none | new hp@0x56546b818428 added connection description "TUNNEL-A" | ike_life: 60s; ipsec_life: 28800s; rekey_margin: 2s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | 192.0.2.254/32===192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org]...192.1.2.45<192.1.2.45>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org]===192.0.1.254/32 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 1.1 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | Added new connection TUNNEL-B with policy ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | No AUTH policy was set - defaulting to RSASIG | ASCII to DN <= "C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org" | ASCII to DN => 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | ASCII to DN => 31 10 30 0e 06 03 55 04 08 13 07 4f 6e 74 61 72 | ASCII to DN => 69 6f 31 10 30 0e 06 03 55 04 07 13 07 54 6f 72 | ASCII to DN => 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 13 09 4c | ASCII to DN => 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | ASCII to DN => 0b 13 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | ASCII to DN => 6e 74 31 23 30 21 06 03 55 04 03 13 1a 77 65 73 | ASCII to DN => 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | ASCII to DN => 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 65 73 | ASCII to DN => 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org is 0 | setting ID to ID_DER_ASN1_DN: 'E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' | loading right certificate 'east' pubkey | unreference key: 0x56546b81ab68 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b81a408 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b81a8b8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b81a398 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b819e08 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b818578 | unreference key: 0x56546b818828 192.1.2.23 cnt 1-- | unreference key: 0x56546b819bf8 east@testing.libreswan.org cnt 1-- | unreference key: 0x56546b81a188 @east.testing.libreswan.org cnt 1-- | unreference key: 0x56546b81a6a8 user-east@testing.libreswan.org cnt 1-- | unreference key: 0x56546b81b1e8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | secrets entry for east already exists | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org is 0 | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports | connect_to_host_pair: 192.1.2.23:500 192.1.2.45:500 -> hp@0x56546b818428: TUNNEL-A added connection description "TUNNEL-B" | ike_life: 60s; ipsec_life: 28800s; rekey_margin: 2s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | 192.0.2.244/32===192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org]...192.1.2.45<192.1.2.45>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org]===192.0.1.254/32 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.528 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | Added new connection TUNNEL-C with policy ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | No AUTH policy was set - defaulting to RSASIG | ASCII to DN <= "C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org" | ASCII to DN => 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | ASCII to DN => 31 10 30 0e 06 03 55 04 08 13 07 4f 6e 74 61 72 | ASCII to DN => 69 6f 31 10 30 0e 06 03 55 04 07 13 07 54 6f 72 | ASCII to DN => 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 13 09 4c | ASCII to DN => 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | ASCII to DN => 0b 13 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | ASCII to DN => 6e 74 31 23 30 21 06 03 55 04 03 13 1a 77 65 73 | ASCII to DN => 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | ASCII to DN => 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 65 73 | ASCII to DN => 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org is 0 | setting ID to ID_DER_ASN1_DN: 'E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' | loading right certificate 'east' pubkey | unreference key: 0x56546b81a6a8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b819e98 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b81b478 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b81b428 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b81b3d8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b81b388 | unreference key: 0x56546b818168 192.1.2.23 cnt 1-- | unreference key: 0x56546b818828 east@testing.libreswan.org cnt 1-- | unreference key: 0x56546b819bf8 @east.testing.libreswan.org cnt 1-- | unreference key: 0x56546b81a188 user-east@testing.libreswan.org cnt 1-- | unreference key: 0x56546b81b9b8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | secrets entry for east already exists | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org is 0 | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports | connect_to_host_pair: 192.1.2.23:500 192.1.2.45:500 -> hp@0x56546b818428: TUNNEL-B added connection description "TUNNEL-C" | ike_life: 60s; ipsec_life: 28800s; rekey_margin: 2s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | 192.0.2.234/32===192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org]...192.1.2.45<192.1.2.45>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org]===192.0.1.254/32 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.484 milliseconds in whack | spent 0.0111 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 792 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 13 ce 9d 4e da e6 3a 63 00 00 00 00 00 00 00 00 | 01 10 02 00 00 00 00 00 00 00 03 18 0d 00 02 84 | 00 00 00 01 00 00 00 01 00 00 02 78 00 01 00 12 | 03 00 00 24 00 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 01 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 04 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 02 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 06 | 80 03 00 03 80 04 00 0e 80 0e 01 00 03 00 00 24 | 03 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 06 80 03 00 03 80 04 00 0e 80 0e 00 80 | 03 00 00 24 04 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 02 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 05 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 02 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 06 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 04 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 07 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 04 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 24 08 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 06 80 03 00 03 80 04 00 05 | 80 0e 01 00 03 00 00 24 09 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 06 80 03 00 03 | 80 04 00 05 80 0e 00 80 03 00 00 24 0a 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 02 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 0b 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 02 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 20 0c 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 0e | 03 00 00 20 0d 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 0e | 03 00 00 20 0e 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 0e | 03 00 00 20 0f 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 05 | 03 00 00 20 10 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 05 | 00 00 00 20 11 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 05 | 0d 00 00 14 40 48 b7 d5 6e bc e8 85 25 e7 de 7f | 00 d6 c2 d3 0d 00 00 14 af ca d7 13 68 a1 f1 c9 | 6b 86 96 fc 77 57 01 00 0d 00 00 14 4a 13 1c 81 | 07 03 58 45 5c 57 28 f2 0e 95 45 2f 0d 00 00 14 | 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d 56 | 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 81 b5 | ec 42 7b 1f 00 00 00 14 cd 60 46 43 35 df 21 f8 | 7c fd b2 fc 68 b6 a4 48 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 00 00 00 00 00 00 00 00 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 792 (0x318) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: IKEv1 state not found (find_state_ikev1_init) | #null state always idle | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x2 opt: 0x2080 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 644 (0x284) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 20 (0x14) | message 'main_inI1_outR1' HASH payload not checked early | received Vendor ID payload [FRAGMENTATION] | received Vendor ID payload [Dead Peer Detection] | quirks.qnat_traversal_vid set to=117 [RFC 3947] | received Vendor ID payload [RFC 3947] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] | in statetime_start() with no state | find_host_connection local=192.1.2.23:500 remote=192.1.2.45:500 policy=IKEV1_ALLOW but ignoring ports | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports | find_next_host_connection policy=IKEV1_ALLOW | found policy = RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (TUNNEL-C) | find_next_host_connection returns TUNNEL-C | find_next_host_connection policy=IKEV1_ALLOW | found policy = RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (TUNNEL-B) | find_next_host_connection returns TUNNEL-B | find_next_host_connection policy=IKEV1_ALLOW | found policy = RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (TUNNEL-A) | find_next_host_connection returns TUNNEL-A | find_next_host_connection policy=IKEV1_ALLOW | find_next_host_connection returns empty | creating state object #1 at 0x56546b81d4c8 | State DB: adding IKEv1 state #1 in UNDEFINED | pstats #1 ikev1.isakmp started | #1 updating local interface from to 192.1.2.23:500 using md->iface (in update_ike_endpoints() at state.c:2669) | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in main_inI1_outR1() at ikev1_main.c:667) | parent state #1: UNDEFINED(ignore) => MAIN_R0(half-open IKE SA) | sender checking NAT-T: enabled; VID 117 | returning NAT-T method NAT_TRAVERSAL_METHOD_IETF_RFC | enabling possible NAT-traversal with method RFC 3947 (NAT-Traversal) "TUNNEL-C" #1: responding to Main Mode | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 1:ISAKMP_NEXT_SA | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 632 (0x278) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 18 (0x12) | *****parse ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | length: 36 (0x24) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | OAKLEY proposal verified unconditionally; no alg_info to check against | Oakley Transform 0 accepted | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | emitting 28 raw bytes of attributes into ISAKMP Transform Payload (ISAKMP) | attributes 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 04 | attributes 80 03 00 03 80 04 00 0e 80 0e 01 00 | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | out_vid(): sending [FRAGMENTATION] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 40 48 b7 d5 6e bc e8 85 25 e7 de 7f 00 d6 c2 d3 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [Dead Peer Detection] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID af ca d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [RFC 3947] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | emitting length of ISAKMP Vendor ID Payload: 20 | no IKEv1 message padding required | emitting length of ISAKMP Message: 144 | complete v1 state transition with STF_OK | [RE]START processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle | doing_xauth:no, t_xauth_client_done:no | peer supports fragmentation | peer supports DPD | IKEv1: transition from state STATE_MAIN_R0 to state STATE_MAIN_R1 | parent state #1: MAIN_R0(half-open IKE SA) => MAIN_R1(open IKE SA) | event_already_set, deleting event | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 144 bytes for STATE_MAIN_R0 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #1) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 01 10 02 00 00 00 00 00 00 00 00 90 0d 00 00 38 | 00 00 00 01 00 00 00 01 00 00 00 2c 00 01 00 01 | 00 00 00 24 00 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 0d 00 00 14 40 48 b7 d5 6e bc e8 85 | 25 e7 de 7f 00 d6 c2 d3 0d 00 00 14 af ca d7 13 | 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 00 00 00 14 | 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | !event_already_set at reschedule | event_schedule: new EVENT_SO_DISCARD-pe@0x56546b81a948 | inserting event EVENT_SO_DISCARD, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x56546b8173c8 size 128 "TUNNEL-C" #1: STATE_MAIN_R1: sent MR1, expecting MI2 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 2.09 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00978 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 396 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | 60 61 8b b1 3e 52 e1 90 e2 69 3a b3 c6 c1 a3 74 | d1 61 99 82 54 25 22 82 16 8e 4b e5 1a 6b 2e 37 | c3 32 77 84 ab 69 51 b1 90 58 3e ea e5 35 e9 f8 | d6 db 8b 93 cc 35 c9 2f 1d 25 c2 58 6e 4d 50 05 | 4b 24 e6 0d 57 32 f9 d5 35 77 08 7b 56 70 0a 57 | 06 fa fa d2 62 a1 e4 c1 96 1c 67 44 31 f8 97 58 | 9d 8a 97 b4 b5 db d2 57 fd a8 6a d2 81 3c d0 26 | fe eb e2 4a ac 40 5d b3 65 f6 13 13 a0 a5 47 d1 | 2d eb 74 9d fc d3 08 56 51 bf 7f 7e 37 0f 27 f2 | e3 0e 38 43 b9 be 8a e1 14 07 81 43 f7 b8 b3 98 | ce 38 78 11 c1 de 56 cf bc 1b b5 a8 2f 7b c9 c5 | af aa e8 b6 d9 02 d8 1c 29 ed 22 25 35 c6 a5 06 | 3a cf bf 39 ca 3c fe c7 6b 16 d0 2b 88 d7 83 1c | 9e df 98 f7 40 a0 2a fa 04 67 90 2b ae e4 23 e3 | aa c2 36 66 d1 f2 dd 5f dd 81 38 c7 fa 34 43 ed | 81 c9 ff cd f2 da 72 ea 2f 30 09 f7 34 b0 7e 05 | 14 00 00 24 41 48 ce 59 ae 8c 0a f5 92 ba 67 8f | 9c ca dc 37 3e 56 5f d2 44 90 1f 90 7a b3 d0 99 | 50 6a d0 99 14 00 00 24 e6 34 0a b5 b0 1c 19 f6 | 4e ef 3f 2b 2b 2d d3 5f e2 44 7e ff b6 f1 bd fa | 4d ea b5 71 9e 48 8e e9 00 00 00 24 5c 47 b2 7a | e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 2b c5 e2 c8 | 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_KE (0x4) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 396 (0x18c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #1 in MAIN_R1 (find_state_ikev1) | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1459) | #1 is idle | #1 idle | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x410 opt: 0x102080 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 260 (0x104) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x102080 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | message 'main_inI2_outR2' HASH payload not checked early | init checking NAT-T: enabled; RFC 3947 (NAT-Traversal) | natd_hash: hasher=0x56546aadcca0(32) | natd_hash: icookie= 13 ce 9d 4e da e6 3a 63 | natd_hash: rcookie= 77 51 4f 24 9b f8 4c 14 | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= e6 34 0a b5 b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f | natd_hash: hash= e2 44 7e ff b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | natd_hash: hasher=0x56546aadcca0(32) | natd_hash: icookie= 13 ce 9d 4e da e6 3a 63 | natd_hash: rcookie= 77 51 4f 24 9b f8 4c 14 | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= 5c 47 b2 7a e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 | natd_hash: hash= 2b c5 e2 c8 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | expected NAT-D(me): e6 34 0a b5 b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f | expected NAT-D(me): e2 44 7e ff b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | expected NAT-D(him): | 5c 47 b2 7a e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 | 2b c5 e2 c8 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | received NAT-D: e6 34 0a b5 b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f | received NAT-D: e2 44 7e ff b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | received NAT-D: 5c 47 b2 7a e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 | received NAT-D: 2b c5 e2 c8 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | NAT_TRAVERSAL encaps using auto-detect | NAT_TRAVERSAL this end is NOT behind NAT | NAT_TRAVERSAL that end is NOT behind NAT | NAT_TRAVERSAL nat-keepalive enabled 192.1.2.45 | NAT-Traversal: Result using RFC 3947 (NAT-Traversal) sender port 500: no NAT detected | NAT_T_WITH_KA detected | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | adding inI2_outR2 KE work-order 1 for state #1 | state #1 requesting EVENT_SO_DISCARD to be deleted | libevent_free: release ptr-libevent@0x56546b8173c8 | free_event_entry: release EVENT_SO_DISCARD-pe@0x56546b81a948 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x56546b81a948 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x56546b81d2e8 size 128 | complete v1 state transition with STF_SUSPEND | crypto helper 0 resuming | [RE]START processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2648) | crypto helper 0 starting work-order 1 for state #1 | suspending state #1 and saving MD | crypto helper 0 doing build KE and nonce (inI2_outR2 KE); request ID 1 | #1 is busy; has a suspended MD | #1 spent 0.446 milliseconds in process_packet_tail() | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.922 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 0 finished build KE and nonce (inI2_outR2 KE); request ID 1 time elapsed 0.002756 seconds | (#1) spent 2.75 milliseconds in crypto helper computing work-order 1: inI2_outR2 KE (pcr) | crypto helper 0 sending results from work-order 1 for state #1 to event queue | scheduling resume sending helper answer for #1 | libevent_malloc: new ptr-libevent@0x7f8644002888 size 128 | crypto helper 0 waiting (nothing to do) | processing resume sending helper answer for #1 | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 0 replies to request ID 1 | calling continuation function 0x56546aa07b50 | main_inI2_outR2_continue for #1: calculated ke+nonce, sending R2 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value c1 44 86 cc 77 92 e1 e7 ee 57 8d 15 8d 24 9f 7d | keyex value f8 36 2b db 2d 7b 18 95 39 59 6c a9 fd 60 cd 0c | keyex value 8a ad a0 49 2a ba fe 6a f7 04 87 fd 5c 9a 04 be | keyex value 08 a6 2a 0b ef fc 35 d2 1d 79 9f 31 43 68 68 7b | keyex value 79 0f 78 bb 7d 47 67 8e e0 b1 a2 58 e9 91 3a ae | keyex value f4 8b 33 a3 b7 93 bf 61 42 ce 72 3b fb c0 68 2e | keyex value 0e 35 b1 8a 1f d8 c6 bb 7f bd 69 bf 06 7b f0 df | keyex value 77 60 5d 47 60 49 8b 86 2d 41 ae 73 83 df 89 8e | keyex value be fa 08 a3 a5 35 1d 83 d3 82 b7 9d 67 1b 47 b0 | keyex value ac ad ab 0e ab 14 01 bc 1a e3 a9 c8 2c 68 bf 44 | keyex value e5 1d a1 41 0f 33 5f d9 b3 15 95 1b 63 93 7a 53 | keyex value 02 da 2d de 93 97 eb 18 07 5f 69 50 17 43 4e b5 | keyex value a5 a4 51 e3 26 43 a6 51 1a e4 88 37 2c f5 d0 be | keyex value 82 81 59 2a 91 d3 73 95 36 b7 03 5e 29 3a 50 6b | keyex value 41 fb 1c 9e fd 3a be 64 21 31 be b5 09 68 f6 df | keyex value f8 e4 fb ab 08 41 de c1 00 50 c3 11 fe 6d 5a 87 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Nr into ISAKMP Nonce Payload | Nr 37 f3 a1 2a a8 71 2f 0c c6 cf 70 8f fa 15 b0 0a | Nr de 89 45 58 0f 34 96 81 f9 b6 e6 7c 49 cd 05 63 | emitting length of ISAKMP Nonce Payload: 36 | sending NAT-D payloads | natd_hash: hasher=0x56546aadcca0(32) | natd_hash: icookie= 13 ce 9d 4e da e6 3a 63 | natd_hash: rcookie= 77 51 4f 24 9b f8 4c 14 | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= 5c 47 b2 7a e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 | natd_hash: hash= 2b c5 e2 c8 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | next payload chain: ignoring supplied 'ISAKMP NAT-D Payload'.'next payload type' value 20:ISAKMP_NEXT_NATD_RFC | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D 5c 47 b2 7a e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 | NAT-D 2b c5 e2 c8 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | emitting length of ISAKMP NAT-D Payload: 36 | natd_hash: hasher=0x56546aadcca0(32) | natd_hash: icookie= 13 ce 9d 4e da e6 3a 63 | natd_hash: rcookie= 77 51 4f 24 9b f8 4c 14 | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= e6 34 0a b5 b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f | natd_hash: hash= e2 44 7e ff b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP NAT-D Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D e6 34 0a b5 b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f | NAT-D e2 44 7e ff b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | emitting length of ISAKMP NAT-D Payload: 36 | no IKEv1 message padding required | emitting length of ISAKMP Message: 396 | main inI2_outR2: starting async DH calculation (group=14) | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding main_inI2_outR2_tail work-order 2 for state #1 | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x56546b81d2e8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x56546b81a948 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x56546b81a948 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x56546b81e5c8 size 128 | #1 main_inI2_outR2_continue1_tail:1165 st->st_calculating = FALSE; | complete v1 state transition with STF_OK | [RE]START processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle; has background offloaded task | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2 | parent state #1: MAIN_R1(open IKE SA) => MAIN_R2(open IKE SA) | event_already_set, deleting event | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x56546b81e5c8 | crypto helper 1 resuming | crypto helper 1 starting work-order 2 for state #1 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x56546b81a948 | crypto helper 1 doing compute dh+iv (V1 Phase 1) (main_inI2_outR2_tail); request ID 2 | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 396 bytes for STATE_MAIN_R1 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #1) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | c1 44 86 cc 77 92 e1 e7 ee 57 8d 15 8d 24 9f 7d | f8 36 2b db 2d 7b 18 95 39 59 6c a9 fd 60 cd 0c | 8a ad a0 49 2a ba fe 6a f7 04 87 fd 5c 9a 04 be | 08 a6 2a 0b ef fc 35 d2 1d 79 9f 31 43 68 68 7b | 79 0f 78 bb 7d 47 67 8e e0 b1 a2 58 e9 91 3a ae | f4 8b 33 a3 b7 93 bf 61 42 ce 72 3b fb c0 68 2e | 0e 35 b1 8a 1f d8 c6 bb 7f bd 69 bf 06 7b f0 df | 77 60 5d 47 60 49 8b 86 2d 41 ae 73 83 df 89 8e | be fa 08 a3 a5 35 1d 83 d3 82 b7 9d 67 1b 47 b0 | ac ad ab 0e ab 14 01 bc 1a e3 a9 c8 2c 68 bf 44 | e5 1d a1 41 0f 33 5f d9 b3 15 95 1b 63 93 7a 53 | 02 da 2d de 93 97 eb 18 07 5f 69 50 17 43 4e b5 | a5 a4 51 e3 26 43 a6 51 1a e4 88 37 2c f5 d0 be | 82 81 59 2a 91 d3 73 95 36 b7 03 5e 29 3a 50 6b | 41 fb 1c 9e fd 3a be 64 21 31 be b5 09 68 f6 df | f8 e4 fb ab 08 41 de c1 00 50 c3 11 fe 6d 5a 87 | 14 00 00 24 37 f3 a1 2a a8 71 2f 0c c6 cf 70 8f | fa 15 b0 0a de 89 45 58 0f 34 96 81 f9 b6 e6 7c | 49 cd 05 63 14 00 00 24 5c 47 b2 7a e3 b1 25 85 | ab 2b 38 d0 b4 af 57 70 2b c5 e2 c8 8d 23 2a 34 | ce d6 24 c2 f3 5b 6d 87 00 00 00 24 e6 34 0a b5 | b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f e2 44 7e ff | b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | !event_already_set at reschedule | event_schedule: new EVENT_RETRANSMIT-pe@0x56546b81a948 | inserting event EVENT_RETRANSMIT, timeout in 0.5 seconds for #1 | libevent_malloc: new ptr-libevent@0x56546b81e5c8 size 128 | #1 STATE_MAIN_R2: retransmits: first event in 0.5 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11182.131943 "TUNNEL-C" #1: STATE_MAIN_R2: sent MR2, expecting MI3 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #1 suppresed complete_v1_state_transition() | #1 spent 1.18 milliseconds in resume sending helper answer | stop processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f8644002888 | crypto helper 1 finished compute dh+iv (V1 Phase 1) (main_inI2_outR2_tail); request ID 2 time elapsed 0.003805 seconds | (#1) spent 3.78 milliseconds in crypto helper computing work-order 2: main_inI2_outR2_tail (pcr) | crypto helper 1 sending results from work-order 2 for state #1 to event queue | scheduling resume sending helper answer for #1 | libevent_malloc: new ptr-libevent@0x7f863c000f48 size 128 | crypto helper 1 waiting (nothing to do) | processing resume sending helper answer for #1 | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 1 replies to request ID 2 | calling continuation function 0x56546aa07b50 | main_inI2_outR2_calcdone for #1: calculate DH finished | [RE]START processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in main_inI2_outR2_continue2() at ikev1_main.c:1015) | stop processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in main_inI2_outR2_continue2() at ikev1_main.c:1028) | resume sending helper answer for #1 suppresed complete_v1_state_transition() | #1 spent 0.0875 milliseconds in resume sending helper answer | processing: STOP state #0 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f863c000f48 | spent 0.00534 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 1884 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 05 10 02 01 00 00 00 00 00 00 07 5c 60 63 1a a6 | 1a 83 e8 e2 a9 6a 05 3a 9e 20 5c 28 27 f6 10 b4 | 38 0e 50 43 01 fd 1b 89 8a b2 c7 71 4b 56 a8 9a | 0b 0c ed e8 5c 51 91 0c d9 ac 1e 83 19 e8 21 18 | ab 8d b7 c0 79 15 89 42 59 1a e3 90 f8 7b c7 28 | 0c c5 60 ff 96 5e f0 bd d6 92 86 72 cf 11 34 1d | d9 61 ba f0 ec 4c 0a 74 8f bc 0d 63 cf a3 4d da | b4 a5 25 aa ea 3f 18 80 8e 73 ad e9 0f 54 e3 62 | 9d fc 0d 6f 57 db 86 ba 68 f4 07 bd 2b 2e e6 fd | 27 e3 27 3d 99 93 2f 8e 44 2e 3b 24 a5 3a c9 ae | 95 dc 7a 31 d8 8b d5 6e 44 b2 d8 ac 6c f5 03 de | 16 70 ac ad 56 12 1d 51 c8 a1 34 0a 95 11 27 c3 | 25 75 5e 95 ff d0 c2 fc b3 96 dd dd 7f 39 20 64 | 54 14 c0 e9 a2 0d 9b 58 fb 42 e6 18 91 bd 15 36 | 49 2f 79 bb 95 08 c2 f3 66 55 a0 c4 d1 60 cd 5d | d7 9f 17 79 ef 34 31 52 b0 3f 3c d5 8b 6a 8a 87 | d6 73 a0 55 ce 77 a5 0e 8c 2d 36 e6 f7 35 95 a0 | d4 22 0c 5d d2 31 4e 33 af 07 3c ae 0f a2 82 87 | 74 67 e4 cc d0 7b ce b6 82 13 94 02 f6 40 60 21 | bd 77 b6 68 ca 51 df 28 9c 49 f9 cf ae 4f a0 e1 | 9a 26 5a f4 5c 4e f5 7a 6b b1 ad 68 10 6e 02 86 | 10 83 69 fa 6a 75 59 4f 5c b0 50 25 e4 11 ef 60 | 92 95 57 71 f6 7b 15 3e b9 92 e7 e0 c2 69 d0 35 | 5d 80 d3 b9 9e 69 95 bc c5 dd 77 f4 ab 27 3f d5 | b6 67 33 7d 0f ab 84 e6 4f 0f f6 ec ba 01 ad 66 | 90 a9 ff f7 b2 7b a3 7a 71 d6 8e 22 26 58 1d 01 | 00 cc c6 ad 6f 83 d7 cb 06 5b 49 50 6f 27 0a 3c | 79 ec 33 5a 29 47 18 b1 d8 3d 00 bf 3c 46 4e 21 | eb 30 57 82 78 68 44 bf b9 1d a6 1a 96 32 d0 bc | ea 19 32 f4 bf 33 49 88 3c db 19 f1 22 43 7d ea | 5f 1f 61 1c ea 10 38 dd 42 e4 64 75 2f 4d 92 25 | 08 a7 e0 c0 55 17 7c 81 3b 0e 11 be 6e 5a 40 ff | 54 7e f9 8b 0b 31 e6 52 44 4b d3 b2 d8 31 7a 20 | 5e 0d bf 4e 7c 0e cf a3 d7 b4 7a 9b 17 57 ee 66 | 23 12 a2 c5 f7 f4 a8 90 74 3b 0a ef 98 7a b5 1c | c0 df 1d 5c 3d 83 e0 27 0e 20 fa 85 b0 59 8e 34 | f6 e6 30 94 b8 5e 33 63 d4 ae a7 a4 db 44 bc 9b | 28 d8 be e4 bf 9b cd b2 2a 45 d0 68 74 20 c5 1f | 89 f1 f5 73 77 de ce bb 25 e1 e6 36 22 58 8b 0a | 29 1e 01 ed de 23 21 3a 32 32 ad f6 3b 5b 67 98 | 67 21 f5 4c 96 b1 1b 8c 51 75 8c 2d 86 09 e8 66 | d7 dc f4 a1 ed ce b8 6c 4a ed 52 af 6b 60 fc 93 | 0f e0 c7 b1 77 c3 4a 82 90 a0 80 2c fd e1 5d ad | 88 d8 48 2d f2 e6 ee d2 06 e6 d3 1f 79 7c 8f 49 | 69 cb c2 ed 76 62 5f 60 11 56 be ad f2 d4 4c c5 | 9a c7 e1 d3 ad 4c 1d 6d 8f 99 3b 1b 6b b3 5b bb | 6f 6a c6 4b 34 53 ee c5 52 f7 b5 af dc 88 50 f3 | 09 95 5e 45 b1 8a a0 26 ee fa e8 7a 35 d1 12 e8 | a8 fb 26 f8 cb 8f 06 67 e0 04 7f e3 49 64 0e 91 | 5c 06 c5 12 29 bd 5d 1a 56 95 8d 00 63 af 7f 70 | b8 77 ab 95 75 8c 28 e8 68 75 9e d2 91 35 70 00 | 6c f4 d5 90 00 56 c7 1d 79 0f c9 bf dd dd fd b9 | c3 13 65 71 d3 b3 49 ed 92 96 c6 58 fc da 21 ba | 32 65 fa f3 ad 81 c7 da b8 16 d2 63 42 40 87 6f | 50 40 cb 5b ee 4b 74 9c da 9b d0 86 a9 39 de ef | b2 4e b1 2f 25 6d 09 c6 4c 70 0b ae ae a0 4e fc | 74 a2 32 bd 33 ca 7c db 88 77 70 0b 4a 25 62 df | 9e ee 74 b8 1a a6 95 d8 3e 85 ea bf 7e e4 d7 73 | 04 d9 68 8f a2 00 12 e9 fe 70 3b c5 d5 74 a1 3e | 2c 37 d2 8b dc 52 f0 2d 55 65 de 9b 18 b4 91 de | 13 71 35 9e 08 60 30 e9 d7 40 ed cb ad 47 f8 2c | 9b ca 3e 69 ea 08 d4 74 66 8a db 89 4a 3b 14 8e | 65 89 56 33 91 88 07 60 45 6e 2c 3b 8c 1e c3 05 | fd 6d 6f 80 5c 52 11 3d b2 cc d4 6e 89 b9 6c 2d | 47 9b e1 56 13 26 4c 89 a5 cc fd fa b9 e4 fd 7d | 1d 62 44 be e2 c7 15 ee 0b f6 8f b2 64 15 1f 6b | 66 15 a7 0c 48 5c 28 d1 18 53 ff de 58 fa 6b 01 | dd eb 75 89 3e bd 59 18 6b 7c 96 bd fb d6 c3 a9 | 69 37 fe c3 49 86 ef 6b 52 2c 28 26 01 88 f0 53 | 7b ab 23 87 cc af ef 31 dd 1b b6 ae 42 46 60 69 | 2f 10 26 eb dc 6c be db e8 27 4c b7 62 63 94 70 | f3 ea 81 c5 de 2d 49 54 7e 60 13 15 58 b8 c4 94 | 50 ca 46 63 a1 33 3d 0d 08 9b 20 4e 0c bd d1 df | 9c 8a 1b 06 ab e7 d9 3e 44 35 7e a5 d9 4c ad eb | 52 85 cb 5a 37 d0 c0 b3 e0 76 0e a9 68 dc 4b 2d | 7f 98 58 88 51 a4 15 7e 07 c0 25 37 87 c2 04 e3 | 28 2d 91 69 26 c2 1d 0f 60 53 d5 e8 11 fd 57 d6 | cd 17 07 38 16 95 d7 71 5b a9 13 92 e5 3a 5f 8b | 59 3f 99 ea 93 c6 ac 68 8f 13 e0 c4 f3 ee 84 2a | 25 07 14 dd 50 66 a7 30 45 80 fc 57 dc ee 1a 72 | e4 26 50 a4 a2 05 49 4d 1f dc da 97 1d f7 32 7e | 30 99 dd b6 29 24 96 e1 91 9a 8d 6c 5f 04 a4 0f | 37 0e f3 75 4a 14 94 86 30 9d 17 1d 44 d8 3a 2f | 6b eb 6d 51 82 33 d4 7c 09 b4 82 e4 40 0b ce f9 | f4 fc 14 4c 92 87 da 71 ba 73 ee a8 78 e9 ec b8 | e5 64 4e ad 9d f7 f6 79 ef 9e a6 d4 79 e6 e6 95 | fd f0 8d 44 4c a0 c1 5e de 26 ad bb d9 60 5b 1a | 70 56 90 8a 70 cc 79 f4 42 87 78 26 70 97 d0 72 | 3c af f0 00 0d 38 45 67 29 b2 e3 07 62 5f 90 07 | b2 99 f6 7c 72 40 f0 31 1f f8 85 44 dc 89 a5 e5 | 20 a2 5b df 2c 4b e5 4b 77 41 3f e5 c0 fb 44 f8 | ff 57 19 95 e5 53 58 5b 87 9d da 0c e4 de 80 bf | d0 5a f0 38 f6 2f 23 05 80 be d3 80 25 54 0c 32 | c0 42 d7 ae 5c b1 ee bf c6 28 d1 1c bd 7d 05 23 | 31 a5 89 ac bc c1 95 eb 79 fd 99 11 d2 cc 91 90 | 8f fd c9 ff 93 c3 3a f3 e7 d4 99 c2 9b 26 af 8c | 28 cf 51 65 f6 c4 c9 e6 ac 3a e2 6d 32 7c 20 41 | 1a ce 6b bb 40 cb 52 2a ce 99 51 18 b4 f5 98 cf | b5 bf 0b 96 3b 53 ca 8f d4 af 9e ca a1 f8 c1 97 | 31 14 91 4d 7a 3a e7 e0 13 3a 5f 7b 59 b6 0a 58 | 19 f9 6d b7 c3 7d 1c 63 a7 8f ce c5 f0 c0 55 cc | 85 f7 9c 62 48 65 5a 6b b8 49 5b d6 b0 d2 b6 c8 | ff 4f 5f 98 e2 a7 22 4f a8 2d bc 45 00 5d 3c e7 | 74 0f aa 54 97 cc 58 b4 41 bd e3 5b 5e c4 d6 2a | f9 c6 32 7d 20 c7 0b 60 61 06 e2 84 2b 44 78 ca | ab be 74 7a 1b b4 8a 3c 0e 71 7f 22 18 b4 4e 92 | b3 12 be f5 fb 4b c9 31 f4 88 ae 33 cc 10 9f f0 | 62 75 62 fc ce ab 17 0e af e3 3c ab 3b b6 f8 23 | fe f3 5c 3b a2 ce c9 82 9f 35 d0 e5 fe 15 73 3b | d6 ea e8 46 cd 5c 09 a8 b1 e7 0b e5 77 97 3e 00 | 8a 11 7a 23 54 a6 84 8d 93 9a 77 7a 13 ac d5 6a | d5 ba 9d ca 03 4c cf 83 f8 98 30 73 7f c6 9e bb | c6 64 a6 a4 5d 6a a0 96 d5 71 b4 12 d4 68 25 bc | 01 b6 83 75 34 2f 09 03 57 69 f7 27 83 52 2a 9d | dd ab 9c b1 c4 0b 69 d0 00 d1 dd 81 c9 fb ee 31 | e2 05 5a 65 2a 37 d0 c6 97 a8 90 0e 01 1a 3d 5b | 9a 0d 23 cd 95 83 59 75 d8 7b d3 1a | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_ID (0x5) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | length: 1884 (0x75c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #1 in MAIN_R2 (find_state_ikev1) | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1459) | #1 is idle | #1 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x220 opt: 0x20c0 | ***parse ISAKMP Identification Payload: | next payload type: ISAKMP_NEXT_CERT (0x6) | length: 191 (0xbf) | ID type: ID_DER_ASN1_DN (0x9) | DOI specific A: 0 (0x0) | DOI specific B: 0 (0x0) | obj: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | obj: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | obj: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | obj: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | obj: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | obj: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | obj: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 77 65 73 | obj: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | obj: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 65 73 | obj: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 | got payload 0x40 (ISAKMP_NEXT_CERT) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_CR (0x7) | length: 1265 (0x4f1) | cert encoding: CERT_X509_SIGNATURE (0x4) | got payload 0x80 (ISAKMP_NEXT_CR) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Certificate RequestPayload: | next payload type: ISAKMP_NEXT_SIG (0x9) | length: 5 (0x5) | cert type: CERT_X509_SIGNATURE (0x4) | got payload 0x200 (ISAKMP_NEXT_SIG) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 388 (0x184) | removing 7 bytes of padding | message 'main_inI3_outR3' HASH payload not checked early | DER ASN1 DN: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | DER ASN1 DN: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | DER ASN1 DN: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | DER ASN1 DN: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | DER ASN1 DN: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | DER ASN1 DN: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | DER ASN1 DN: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 77 65 73 | DER ASN1 DN: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | DER ASN1 DN: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 65 73 | DER ASN1 DN: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 "TUNNEL-C" #1: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' | global one-shot timer EVENT_FREE_ROOT_CERTS scheduled in 300 seconds loading root certificate cache | spent 5.81 milliseconds in get_root_certs() calling PK11_ListCertsInSlot() | spent 0.0266 milliseconds in get_root_certs() filtering CAs | #1 spent 5.87 milliseconds in find_and_verify_certs() calling get_root_certs() | checking for known CERT payloads | saving certificate of type 'X509_SIGNATURE' | decoded cert: E=user-west@testing.libreswan.org,CN=west.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #1 spent 0.836 milliseconds in find_and_verify_certs() calling decode_cert_payloads() | cert_issuer_has_current_crl: looking for a CRL issued by E=testing@libreswan.org,CN=Libreswan test CA for mainca,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #1 spent 0.0536 milliseconds in find_and_verify_certs() calling crl_update_check() | missing or expired CRL | crl_strict: 0, ocsp: 0, ocsp_strict: 0, ocsp_post: 0 | verify_end_cert trying profile IPsec | certificate is valid (profile IPsec) | #1 spent 0.153 milliseconds in find_and_verify_certs() calling verify_end_cert() "TUNNEL-C" #1: certificate verified OK: E=user-west@testing.libreswan.org,CN=west.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b831018 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b830658 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b8304a8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b82f318 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b837698 | unreference key: 0x56546b837728 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 1-- | #1 spent 0.427 milliseconds in decode_certs() calling add_pubkey_from_nss_cert() | #1 spent 7.38 milliseconds in decode_certs() | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' needs further ID comparison against 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' matched our ID | SAN ID matched, updating that.cert | X509: CERT and ID matches current connection | CR | requested CA: '%any' | refine_host_connection for IKEv1: starting with "TUNNEL-C" | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | refine_host_connection: checking "TUNNEL-C" against "TUNNEL-C", best=(none) with match=1(id=1(0)/ca=1(7)/reqca=1(0)) | Warning: not switching back to template of current instance | No IDr payload received from peer | refine_host_connection: checked TUNNEL-C against TUNNEL-C, now for see if best | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAbEef vs PKK_RSA:AwEAAbEef | refine_host_connection: picking new best "TUNNEL-C" (wild=0, peer_pathlen=7/our=0) | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | refine_host_connection: checking "TUNNEL-C" against "TUNNEL-B", best=TUNNEL-C with match=1(id=1(0)/ca=1(7)/reqca=1(0)) | Warning: not switching back to template of current instance | No IDr payload received from peer | refine_host_connection: checked TUNNEL-C against TUNNEL-B, now for see if best | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAbEef vs PKK_RSA:AwEAAbEef | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | refine_host_connection: checking "TUNNEL-C" against "TUNNEL-A", best=TUNNEL-C with match=1(id=1(0)/ca=1(7)/reqca=1(0)) | Warning: not switching back to template of current instance | No IDr payload received from peer | refine_host_connection: checked TUNNEL-C against TUNNEL-A, now for see if best | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAbEef vs PKK_RSA:AwEAAbEef | refine going into 2nd loop allowing instantiated conns as well | returning since no better match than original best_found | offered CA: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | required RSA CA is '%any' | checking RSA keyid 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' for match with 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | key issuer CA is 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | an RSA Sig check passed with *AwEAAZd0v [remote certificates] | #1 spent 0.195 milliseconds in try_all_RSA_keys() trying a pubkey "TUNNEL-C" #1: Authenticated using RSA | thinking about whether to send my certificate: | I have RSA key: OAKLEY_RSA_SIG cert.type: CERT_X509_SIGNATURE | sendcert: CERT_ALWAYSSEND and I did not get a certificate request | so send cert. | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_ID (0x5) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 5:ISAKMP_NEXT_ID | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_CERT (0x6) | ID type: ID_DER_ASN1_DN (0x9) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 6:ISAKMP_NEXT_CERT | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 183 raw bytes of my identity into ISAKMP Identification Payload (IPsec DOI) | my identity 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | my identity 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | my identity 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | my identity 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | my identity 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | my identity 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | my identity 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 61 73 | my identity 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | my identity 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | my identity 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | my identity 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | my identity 77 61 6e 2e 6f 72 67 | emitting length of ISAKMP Identification Payload (IPsec DOI): 191 "TUNNEL-C" #1: I am sending my cert | ***emit ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_SIG (0x9) | cert encoding: CERT_X509_SIGNATURE (0x4) | next payload chain: ignoring supplied 'ISAKMP Certificate Payload'.'next payload type' value 9:ISAKMP_NEXT_SIG | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Certificate Payload (6:ISAKMP_NEXT_CERT) | next payload chain: saving location 'ISAKMP Certificate Payload'.'next payload type' in 'reply packet' | emitting 1260 raw bytes of CERT into ISAKMP Certificate Payload | CERT 30 82 04 e8 30 82 04 51 a0 03 02 01 02 02 01 03 | CERT 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 | CERT 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 31 | CERT 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 69 | CERT 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 6f | CERT 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c 69 | CERT 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 0b | CERT 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 6e | CERT 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 72 | CERT 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 6f | CERT 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a 86 | CERT 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e 67 | CERT 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 30 22 | CERT 18 0f 32 30 31 39 30 38 32 34 30 39 30 37 35 33 | CERT 5a 18 0f 32 30 32 32 30 38 32 33 30 39 30 37 35 | CERT 33 5a 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 | CERT 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 | CERT 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 | CERT 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c | CERT 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 | CERT 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 | CERT 6d 65 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 | CERT 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a | CERT 86 48 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 | CERT 61 73 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 30 82 01 a2 30 0d 06 | CERT 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 8f | CERT 00 30 82 01 8a 02 82 01 81 00 b1 1e 7c b3 bf 11 | CERT 96 94 23 ca 97 5e c7 66 36 55 71 49 95 8d 0c 2a | CERT 5c 30 4d 58 29 a3 7b 4d 3b 3f 03 06 46 a6 04 63 | CERT 71 0d e1 59 4f 9c ec 3a 17 24 8d 91 6a a8 e2 da | CERT 57 41 de f4 ff 65 bf f6 11 34 d3 7d 5a 7f 6e 3a | CERT 3b 74 3c 51 2b e4 bf ce 6b b2 14 47 26 52 f5 57 | CERT 28 bc c5 fb f9 bc 2d 4e b9 f8 46 54 c7 95 41 a7 | CERT a4 b4 d3 b3 fe 55 4b df f5 c3 78 39 8b 4e 04 57 | CERT c0 1d 5b 17 3c 28 eb 40 9d 1d 7c b3 bb 0f f0 63 | CERT c7 c0 84 b0 4e e4 a9 7c c5 4b 08 43 a6 2d 00 22 | CERT fd 98 d4 03 d0 ad 97 85 d1 48 15 d3 e4 e5 2d 46 | CERT 7c ab 41 97 05 27 61 77 3d b6 b1 58 a0 5f e0 8d | CERT 26 84 9b 03 20 ce 5e 27 7f 7d 14 03 b6 9d 6b 9f | CERT fd 0c d4 c7 2d eb be ea 62 87 fa 99 e0 a6 1c 85 | CERT 4f 34 da 93 2e 5f db 03 10 58 a8 c4 99 17 2d b1 | CERT bc e5 7b bd af 0e 28 aa a5 74 ea 69 74 5e fa 2c | CERT c3 00 3c 2f 58 d0 20 cf e3 46 8d de aa f9 f7 30 | CERT 5c 16 05 04 89 4c 92 9b 8a 33 11 70 83 17 58 24 | CERT 2a 4b ab be b6 ec 84 9c 78 9c 11 04 2a 02 ce 27 | CERT 83 a1 1f 2b 38 3f 27 7d 46 94 63 ff 64 59 4e 6c | CERT 87 ca 3e e6 31 df 1e 7d 48 88 02 c7 9d fa 4a d7 | CERT f2 5b a5 fd 7f 1b c6 dc 1a bb a6 c4 f8 32 cd bf | CERT a7 0b 71 8b 2b 31 41 17 25 a4 18 52 7d 32 fc 0f | CERT 5f b8 bb ca e1 94 1a 42 4d 1f 37 16 67 84 ae b4 | CERT 32 42 9c 5a 91 71 62 b4 4b 07 02 03 01 00 01 a3 | CERT 82 01 06 30 82 01 02 30 09 06 03 55 1d 13 04 02 | CERT 30 00 30 47 06 03 55 1d 11 04 40 30 3e 82 1a 65 | CERT 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 81 1a 65 61 73 74 40 | CERT 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | CERT 6e 2e 6f 72 67 87 04 c0 01 02 17 30 0b 06 03 55 | CERT 1d 0f 04 04 03 02 07 80 30 1d 06 03 55 1d 25 04 | CERT 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b | CERT 06 01 05 05 07 03 02 30 41 06 08 2b 06 01 05 05 | CERT 07 01 01 04 35 30 33 30 31 06 08 2b 06 01 05 05 | CERT 07 30 01 86 25 68 74 74 70 3a 2f 2f 6e 69 63 2e | CERT 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | CERT 6e 2e 6f 72 67 3a 32 35 36 30 30 3d 06 03 55 1d | CERT 1f 04 36 30 34 30 32 a0 30 a0 2e 86 2c 68 74 74 | CERT 70 3a 2f 2f 6e 69 63 2e 74 65 73 74 69 6e 67 2e | CERT 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 2f 72 65 | CERT 76 6f 6b 65 64 2e 63 72 6c 30 0d 06 09 2a 86 48 | CERT 86 f7 0d 01 01 0b 05 00 03 81 81 00 3a 56 a3 7d | CERT b1 4e 62 2f 82 0d e3 fe 74 40 ef cb eb 93 ea ad | CERT e4 74 8b 80 6f ae 8b 65 87 12 a6 24 0d 21 9c 5f | CERT 70 5c 6f d9 66 8d 98 8b ea 59 f8 96 52 6a 6c 86 | CERT d6 7d ba 37 a9 8c 33 8c 77 18 23 0b 1b 2a 66 47 | CERT e7 95 94 e6 75 84 30 d4 db b8 23 eb 89 82 a9 fd | CERT ed 46 8b ce 46 7f f9 19 8f 49 da 29 2e 1e 97 cd | CERT 12 42 86 c7 57 fc 4f 0a 19 26 8a a1 0d 26 81 4d | CERT 53 f4 5c 92 a1 03 03 8d 6c 51 33 cc | emitting length of ISAKMP Certificate Payload: 1265 | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAbEef vs PKK_RSA:AwEAAbEef | ***emit ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Certificate Payload'.'next payload type' to current ISAKMP Signature Payload (9:ISAKMP_NEXT_SIG) | next payload chain: saving location 'ISAKMP Signature Payload'.'next payload type' in 'reply packet' | emitting 384 raw bytes of SIG_R into ISAKMP Signature Payload | SIG_R 16 5d 22 e5 7c 7d 8a e5 71 51 e7 2f 93 e4 66 c2 | SIG_R b0 dc dc 53 6e 79 c8 92 00 f5 58 5b 1a 7f 9b d8 | SIG_R 2b a5 1e 21 3f 3d 30 a0 ce c6 ed 0c 9e cb 2d 92 | SIG_R 80 7f dc be 75 22 45 13 e2 72 03 2d f8 d1 18 b7 | SIG_R d9 1a 16 63 0d 26 f8 d1 d6 a2 b0 de bb ea 80 ad | SIG_R b9 e5 92 9d e9 e2 ae fa 97 d7 94 c1 de 2b 0d c5 | SIG_R 77 62 52 5f d5 d9 b4 26 b0 b6 d5 bb e1 23 c1 af | SIG_R 21 e4 7f 2a d6 35 97 a6 08 a2 81 03 33 c4 0a 91 | SIG_R 59 5d e2 45 3c c2 a4 af 01 ce e1 b4 de ae f5 7e | SIG_R 21 30 56 93 eb 2c 70 fd 30 20 93 fa ca 89 3f 8a | SIG_R 0a fe e1 56 59 91 ab 58 b9 4c f4 46 29 08 40 58 | SIG_R f9 bf eb 1a ff 54 ec bc 5b 0d c2 39 63 4d d4 61 | SIG_R 56 2a d3 8c 3e 85 a0 21 ff dc eb 12 54 ae 7b 28 | SIG_R b5 a0 5a 33 03 4a 58 34 3c 2a 1e e3 97 dc 29 d8 | SIG_R 66 d5 7d 27 53 54 82 cf b4 dd 01 31 5c 55 c5 c0 | SIG_R 1d 4d 48 bb 7a 3f 20 53 be f9 c3 e0 47 79 03 e4 | SIG_R df 88 38 9d b7 44 f9 de 2d 02 6d de a5 61 67 74 | SIG_R 1d 80 8a 5a 08 64 99 dc 72 ea 5f 8e 6e c3 e2 bb | SIG_R d2 23 d3 4d da f0 9e 80 5f 7b ec 02 fb 52 bc ed | SIG_R 6d 9c ae 7a 60 24 6d 2d 94 47 b4 3d ac f8 7a 75 | SIG_R f1 be bb dc 75 0d 9a 53 bf 21 97 7d db 0b b7 0f | SIG_R 33 3e f4 de b1 fe 44 5f ef cb c7 75 1b 66 c2 43 | SIG_R a2 30 1b a0 5e b3 08 f3 7a 19 26 94 9e a2 aa 03 | SIG_R b1 b9 db 0e c2 50 19 6d e5 00 f0 f5 94 40 da 57 | emitting length of ISAKMP Signature Payload: 388 | emitting 12 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 1884 | FOR_EACH_CONNECTION_... in ISAKMP_SA_established | complete v1 state transition with STF_OK | [RE]START processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3 | parent state #1: MAIN_R2(open IKE SA) => MAIN_R3(established IKE SA) | event_already_set, deleting event | state #1 requesting EVENT_RETRANSMIT to be deleted | #1 STATE_MAIN_R3: retransmits: cleared | libevent_free: release ptr-libevent@0x56546b81e5c8 | free_event_entry: release EVENT_RETRANSMIT-pe@0x56546b81a948 | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 1884 bytes for STATE_MAIN_R2 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #1) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 05 10 02 01 00 00 00 00 00 00 07 5c c7 83 2e f7 | c6 08 43 4c 75 17 70 24 5d a5 fe 70 57 25 c9 ed | 46 a7 ef 35 30 f8 48 ab c9 8c 5e c7 5e de 18 b6 | 68 e3 90 b6 f4 7e bd 09 e7 2f 39 91 3d 90 65 4c | 76 84 4e b0 d1 31 dd 73 44 f7 6f be 13 68 b5 4b | 36 89 71 fc 1d 9e e2 2d bf 08 d5 56 85 5e 53 2f | f4 27 8c 71 23 ca bb 80 dc 5f 7a 93 61 4b 7a 6d | 68 d9 45 0d 4c ca 03 3b 42 5d 4c e0 19 e2 cd 92 | 24 95 5a 6b c8 f0 ce fa c8 02 3a 89 4a da 7c b1 | 42 b1 61 a2 66 41 ef 74 9e 52 ee 5d d6 d2 c3 fc | 88 31 05 6b f5 8a 74 4b cb 37 b5 13 a8 df 29 60 | c1 51 fa 14 14 9a 12 df bb f8 5f 66 ab aa 07 7f | 36 13 01 7d 91 3b 1a 8b 49 cc fb f0 21 ab 39 83 | 6f 92 df 13 1e 3f 0f 7b b1 94 2f ea 91 27 60 c6 | 04 66 0c 91 ef 5a 77 5f d7 f1 25 1f ed 30 5b 73 | 70 56 df c1 eb 8b 38 a7 79 d7 99 1d 5f c4 f2 b1 | 8e ef fb fa b0 b3 2c de 26 90 ed 3d 8c d9 02 0c | 04 1a 16 24 e9 4a 81 a0 52 33 48 7a 99 12 bb 5e | 23 4b 56 3b 3a a2 67 2a cc 31 8e 27 2f f4 de b3 | af 0b f5 d8 30 07 91 16 d6 a0 3b 4f 1d 98 b9 12 | a2 2f 79 7a d8 68 90 ab 33 1c 12 6f 7a 92 e2 78 | 10 92 83 10 8a 60 9e 69 8d 6c 63 aa c8 69 1d d9 | 8c 7d a5 d0 e6 8e 21 78 09 25 61 09 f8 37 fa 0f | 15 52 64 cc 3b ee 6c 0a d7 73 2f 0b 02 54 bd b8 | 44 9b 51 c7 8c b2 2f a8 45 f8 65 ba 7a 1d 57 c8 | f9 e1 79 65 8d 6e 8d 65 c8 28 a1 0d e6 cd 43 22 | 56 8b 6e 5f 50 33 62 6b 15 e1 bf fa 4f 5f 7f 32 | d0 a2 4d 51 5e 70 6f 73 91 8e 47 db 9a ef 2c 4c | a7 90 ac 44 b6 cd f7 c3 6b e8 0f 5d 79 bb dd c7 | 6e 89 f8 9a fd 6f a4 c8 ee 2a c4 63 ff 54 d3 f4 | 64 20 15 86 a9 81 28 1e ec 00 53 97 12 9c cd 78 | 48 0d 0f 08 e6 df 71 05 66 dd 73 6d 3e 20 1d dc | 32 2a 80 83 0d ce 63 5e 72 83 42 e6 a0 6a c5 83 | 74 af 51 c4 b8 10 13 a4 3d 03 fe 9a 9f 64 7b d6 | cd 72 89 f0 91 8b 6c 24 e2 d7 30 48 27 f8 34 5b | ff 05 ad 2c dd 82 a7 7b 44 f5 01 b2 55 e5 57 37 | b5 2e 18 9c b4 9f 58 5b 53 67 7a a4 57 14 4e b3 | ed b5 80 04 7f 4a c3 94 71 1f 60 08 8c ef 57 36 | bd 4f 86 19 50 63 cd 52 d2 a7 9c 0d e8 cb ce ef | d6 a3 4c 0a 60 a4 00 b7 63 a6 5f b5 fe 6e e5 c4 | 3b ad 8e 39 01 45 3b f9 e4 2a f6 60 ef 1d 4f 23 | ce 57 8b 94 a1 0a 21 de c4 ac e4 bb 6b 98 19 e9 | 0f 0d 46 8a 2d 08 56 8a c5 44 ba e1 37 82 29 99 | 02 82 27 77 43 48 5f 09 41 f4 fc da 04 f2 37 ab | d3 a7 ba 79 f6 87 f1 55 c0 d5 f2 7c a8 87 8f 9a | 72 68 bd 5d 1a 78 58 7b b2 1b fc 4c 4b 6c 07 be | 94 82 c2 c3 8f 46 7a 19 57 8f b1 5d 8f 4b b1 66 | 9c b1 f7 04 b7 3d b4 73 7d ef f8 3a 4d fd 1f 18 | 44 c5 1a 51 e1 bc e6 fd 98 bf f2 14 78 97 d0 00 | fd dc 46 2f 9e 5c 67 e3 40 91 b5 9a 12 08 6b fd | 64 81 f1 79 d4 e7 00 e3 4f 16 43 19 15 b0 95 55 | 67 b1 84 20 22 19 f4 0d a5 7c 70 18 4e c2 f1 2b | 95 38 15 af 97 37 78 4c 31 e4 58 94 18 77 76 5c | 3b 56 9f 2b 0e d0 db e3 07 dd b7 e6 7b 1a 4c 51 | 3a d5 46 3f d6 c8 e3 c5 8b e5 82 39 af fb 7d 48 | a1 8e f6 bd be 02 8e 69 48 85 55 99 ba 7d 48 09 | 95 d1 91 12 73 d8 b0 17 57 57 2e 6e a2 e9 1d 1d | a7 e3 0c a2 07 2c 5e 7b 34 14 23 99 c4 b2 26 4d | 4b e5 28 82 fe 1c a1 4d b4 0b 14 61 0d 35 97 a1 | 4d 05 11 39 ff 24 ee cf 27 43 91 ee cf 0b 26 6b | 9b c8 e0 0d a2 af be 3d 67 5f a4 04 62 f3 30 78 | a6 8c 02 61 14 5d b6 e6 66 22 be 28 98 d3 64 74 | 69 57 26 48 55 ce e5 ff 50 72 e3 1a f5 93 db f2 | 71 7d 2f ad a5 a8 60 b2 cc fb e9 05 7c f6 25 7c | 1a 45 32 67 66 fb d9 35 f1 89 33 48 4b 88 f0 b3 | cd 8c c2 bd 12 6c 8b 93 c9 5b a6 ad 0e f8 69 02 | b7 b6 b7 4b b0 16 8d db 5d a0 22 8c 1e bf 16 37 | 57 3f 96 fe 8f 67 31 27 ff 0a e0 b7 7c 92 e8 ff | 59 c7 12 18 cc 49 e5 3d 42 19 df 59 e3 e9 8b f4 | 0b 33 db 27 bd e0 7f 3c 5e 6c 8d da 52 64 3b eb | 46 80 6b 7e c3 e4 ad 0d 30 a7 ea 36 fa 3a 0f ea | 7e e8 b8 02 84 25 75 01 f4 7b 46 ee 72 76 3b b5 | 51 34 90 ee b2 5d ee 5c 1c 3d 69 38 19 93 89 ed | a5 92 75 f9 ab 5f c3 47 39 d2 44 5d 28 3d a3 8f | 17 83 d2 d8 82 2b 92 37 c8 6d 74 28 20 40 c6 3d | 44 29 8a d1 3f 5b b2 1c ce 71 46 ad 71 c6 f7 ed | 81 06 7b 0a 20 d1 9f b3 d3 ff 8f 76 00 89 48 0f | 7a 6c e6 61 6a d8 78 4e de fa f3 b8 66 78 57 a2 | d2 37 9f 4b 6f c1 5e 79 10 b0 43 1a e5 d8 98 2f | 7f 6a a0 7c bc 1e 3a c3 89 8a 85 3f fa b7 0b f4 | dc 25 d8 9b 69 14 ac a5 1c d5 4c a6 2e 4a 08 54 | 42 ad 34 e9 d0 87 ff 22 cc 0a 3b 49 91 54 43 ed | 26 33 49 e2 b7 d7 22 2b 99 69 95 05 51 5f 3b bf | 8c 3a f6 6f 5d 34 fc c6 dd 16 dc 2c 09 f5 12 ac | 09 f2 6c 27 a6 d3 5f c7 8b ff 77 f2 54 6b 69 55 | c4 6c 15 8d 41 ef c2 29 01 dc 08 11 40 14 ef 7a | 55 a4 42 d6 99 22 bb 20 d7 69 51 a3 ac 6c 58 76 | 2a 06 b5 02 de ec e7 24 4c 9a d1 c1 42 65 4c f6 | 23 eb c6 b8 7a e9 d4 11 85 41 6b 68 78 3a ac 08 | 71 d6 b7 a0 40 12 02 34 91 bd 22 68 b6 57 bd 20 | 5f e8 42 ea 84 e6 91 34 ee 4b 16 e4 77 1f 00 d2 | ea fe 57 95 9b 98 3a 85 59 4e dc 36 86 b2 d7 20 | bd db 8c 87 6e 77 72 02 6a fe 19 1e 5c fe 9b bd | be 79 51 bb d8 a7 bd d0 45 c4 8d 0c f6 e3 00 d7 | 24 7a 04 bc 89 ae f1 3b a4 74 3f f3 9b 13 61 f3 | 1d 60 ca 92 bc 9c 3b 7e dc 85 4d e1 a9 a0 c4 06 | ea 0f 00 14 22 21 f7 a1 6f 70 e5 5e 7e 33 1d 62 | 77 7f d1 29 e1 f0 18 a3 8a f4 8b 48 b1 4e 9a d9 | d8 30 2b 32 2c cf 52 d9 4c 4c 0a f6 0e fa 07 2e | 4c 73 c1 89 ca 38 6d fc c8 a1 20 12 6f 32 27 f8 | e9 56 6c 3f 0f 05 63 ff 41 22 be f6 60 9a a7 55 | dc cb 13 fe e9 7a 55 27 a8 37 d4 85 d6 fe e9 fb | d7 4d 5c d1 40 dd 7e c0 dc dd 8c c3 bf ba b4 da | b2 de 2b 66 66 72 aa bf e2 6e 6d 3c ed 38 15 52 | 23 58 44 e7 0b d9 b0 7e 38 48 2d 07 5a bb a1 f0 | c4 ed cc 6a ca cd 3d ba 4e d6 32 43 b7 d3 9f fa | 0c fb 94 be 0a da 26 3c ff 78 aa f1 47 19 e1 90 | 28 eb 96 f0 49 b6 2e 6a d8 9f 36 88 7f bc b2 d4 | bb 36 af 58 da 58 ce 2e f6 ba 0d 1a 85 40 96 d9 | 94 82 b8 b2 b9 16 16 ce c5 97 0f ce 9b 15 71 f6 | cb 0d 38 81 e8 a4 47 b9 f2 47 9c 9f 46 a9 90 d0 | d2 ea e0 fb d0 22 ee 69 bc cf cd 02 b9 88 57 64 | 1e de 71 90 a2 d6 9e df 91 f0 3a 9f f8 4b f8 a3 | 5b 26 ce 29 80 b3 1e 70 eb 40 4b 90 f1 62 bd 17 | c6 e1 33 0e 34 cd af 92 d2 9f 6a 1d 1d a1 ef b3 | ee 03 be 8f c9 15 ea 4d 22 46 73 d8 fe e9 94 0a | 08 f4 05 5b c8 8f cd d3 31 97 19 4f | !event_already_set at reschedule | event_schedule: new EVENT_SA_REPLACE-pe@0x56546b81a948 | inserting event EVENT_SA_REPLACE, timeout in 59 seconds for #1 | libevent_malloc: new ptr-libevent@0x56546b8380d8 size 128 | pstats #1 ikev1.isakmp established "TUNNEL-C" #1: STATE_MAIN_R3: sent MR3, ISAKMP SA established {auth=RSA_SIG cipher=AES_CBC_256 integ=HMAC_SHA2_256 group=MODP2048} | DPD: dpd_init() called on ISAKMP SA | DPD: Peer supports Dead Peer Detection | DPD: not initializing DPD because DPD is disabled locally | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | unpending state #1 | #1 spent 12 milliseconds | #1 spent 20.1 milliseconds in process_packet_tail() | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 20.7 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00455 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 476 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 62 18 48 6d 00 00 01 dc 15 ff 56 3c | 47 38 56 33 81 13 63 2e 80 6b a6 ad 33 0f b2 ce | 9a 30 a9 fd 1a d4 3b 1d 6e d7 50 6f 7d dd b3 f2 | ab 6e a0 d0 81 6f a1 1d ce d6 81 bc f4 72 f2 30 | 54 28 b4 e5 10 ff b5 49 8a a2 78 e2 fb 51 8e 3f | 5c ce a5 e6 87 91 1d 6e 69 1d c4 9e f1 7c b1 61 | df 13 ca a9 0e 8f 2c 8f ee a5 c1 5f 5c bb 92 c8 | 33 54 a5 99 be 55 19 da 93 79 3d ff 56 1a 1c a8 | 33 51 8b 26 37 b7 9f d9 d6 ab 32 f6 c5 21 f2 30 | 8b 80 e0 b4 07 5d 9e 9b cc 66 6c be dd 19 f6 04 | f7 81 c4 cc 18 ca b3 0c ef 32 ee 06 4c 4b 53 18 | 4d 33 13 bf 83 72 81 3a 97 5a 9c e2 af 27 58 a8 | e5 86 84 87 aa 4d 67 5c 7c e1 c2 7a f3 db 31 c3 | 9d 34 6c bb 5e f8 14 1d 21 e1 8e 03 f6 4f 50 eb | 6a af 1e 75 c2 40 cc e0 c7 ec 84 5f 49 86 37 5f | e8 32 8a 3b 5a 91 66 e2 f7 3f 92 07 79 ee 1b 06 | b3 e5 37 78 e0 73 5f 11 80 2b 35 61 b0 7c 83 54 | 17 bc 69 5c 76 15 32 cc b0 a8 a3 87 9b 2f 1b 0b | c9 e8 ab 33 24 4b 28 26 51 4b 98 44 59 b5 26 7d | 93 f4 fb 15 fb 8c a0 f2 c4 cb 96 63 e7 0d b0 89 | 42 7d a8 db cf 59 6d 6e 2e ea cb 6b a7 04 f8 76 | bc bd 3d 8d b0 b2 5d 83 46 b9 5a 55 f1 4f 57 ba | 8b c8 b2 fa cf 0c 14 49 8f 90 28 6f 3a 4d 85 ba | 31 0c 5f fe f1 96 0b 37 f0 bc 46 ba fe 61 f5 64 | 78 71 eb 82 75 49 6d 58 bd 88 7b b9 8a fd e5 18 | 21 9b b8 e6 aa 25 8a 32 5c 4b 19 96 69 a4 ff 99 | 3c c6 88 70 7d 62 db 6d 59 6e e1 26 93 19 70 99 | 60 3f 3d 91 3b b9 0e 38 af a0 97 66 e5 4f e7 23 | 0a 3c 7b a5 c1 fd f9 97 8b 0a f7 15 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 1645758573 (0x6218486d) | length: 476 (0x1dc) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: IKEv1 state not found (find_state_ikev1) | State DB: found IKEv1 state #1 in MAIN_R3 (find_state_ikev1) | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1607) | #1 is idle | #1 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x502 opt: 0x200030 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_SA (0x1) | length: 36 (0x24) | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x402 opt: 0x200030 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 84 (0x54) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x200030 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | length: 36 (0x24) | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | length: 260 (0x104) | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 01 fe | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 02 fe | removing 8 bytes of padding | quick_inI1_outR1 HASH(1): | 85 e1 de 9e cb 08 ed 10 5c 0c be c2 6e 8a 62 ed | d6 55 bb a3 13 69 de 45 fe 6e 57 36 88 0b 9b a2 | received 'quick_inI1_outR1' message HASH(1) data ok | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 01 fe | peer client is 192.0.1.254/32 | peer client protocol/port is 0/0 | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 02 fe | our client is 192.0.2.254/32 | our client protocol/port is 0/0 "TUNNEL-C" #1: the peer proposed: 192.0.2.254/32:0/0 -> 192.0.1.254/32:0/0 | find_client_connection starting with TUNNEL-C | looking for 192.0.2.254/32:0/0 -> 192.0.1.254/32:0/0 | concrete checking against sr#0 192.0.2.234/32 -> 192.0.1.254/32 | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | fc_try trying TUNNEL-C:192.0.2.254/32:0/0 -> 192.0.1.254/32:0/0 vs TUNNEL-C:192.0.2.234/32:0/0 -> 192.0.1.254/32:0/0 | our client (192.0.2.234/32) not in our_net (192.0.2.254/32) | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | fc_try trying TUNNEL-C:192.0.2.254/32:0/0 -> 192.0.1.254/32:0/0 vs TUNNEL-B:192.0.2.244/32:0/0 -> 192.0.1.254/32:0/0 | our client (192.0.2.244/32) not in our_net (192.0.2.254/32) | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | fc_try trying TUNNEL-C:192.0.2.254/32:0/0 -> 192.0.1.254/32:0/0 vs TUNNEL-A:192.0.2.254/32:0/0 -> 192.0.1.254/32:0/0 | fc_try concluding with TUNNEL-A [128] | fc_try TUNNEL-C gives TUNNEL-A | concluding with d = TUNNEL-A | using connection "TUNNEL-A" | client wildcard: no port wildcard: no virtual: no | creating state object #2 at 0x56546b8364c8 | State DB: adding IKEv1 state #2 in UNDEFINED | pstats #2 ikev1.ipsec started | duplicating state object #1 "TUNNEL-C" as #2 for IPSEC SA | #2 setting local endpoint to 192.1.2.23:500 from #1.st_localport (in duplicate_state() at state.c:1484) | in connection_discard for connection TUNNEL-C | start processing: connection "TUNNEL-A" (BACKGROUND) (in quick_inI1_outR1_tail() at ikev1_quick.c:1286) | suspend processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in quick_inI1_outR1_tail() at ikev1_quick.c:1295) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in quick_inI1_outR1_tail() at ikev1_quick.c:1295) | child state #2: UNDEFINED(ignore) => QUICK_R0(established CHILD SA) | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 72 (0x48) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 2 (0x2) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI f3 84 cf fa | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_T (0x3) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified unconditionally; no alg_info to check against | adding quick_outI1 KE work-order 3 for state #2 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x56546b81fed8 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x56546b7eebf8 size 128 | libevent_realloc: release ptr-libevent@0x56546b7ba938 | libevent_realloc: new ptr-libevent@0x56546b813ef8 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #2 and saving MD | #2 is busy; has a suspended MD | crypto helper 3 resuming | crypto helper 3 starting work-order 3 for state #2 | #1 spent 0.32 milliseconds in process_packet_tail() | crypto helper 3 doing build KE and nonce (quick_outI1 KE); request ID 3 | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in process_md() at demux.c:382) | resume processing: connection "TUNNEL-A" (in process_md() at demux.c:382) | stop processing: connection "TUNNEL-A" (in process_md() at demux.c:383) | spent 0.647 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 3 finished build KE and nonce (quick_outI1 KE); request ID 3 time elapsed 0.001055 seconds | (#2) spent 1.06 milliseconds in crypto helper computing work-order 3: quick_outI1 KE (pcr) | crypto helper 3 sending results from work-order 3 for state #2 to event queue | scheduling resume sending helper answer for #2 | libevent_malloc: new ptr-libevent@0x7f8640003f28 size 128 | crypto helper 3 waiting (nothing to do) | processing resume sending helper answer for #2 | start processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 3 replies to request ID 3 | calling continuation function 0x56546aa07b50 | quick_inI1_outR1_cryptocontinue1 for #2: calculated ke+nonce, calculating DH | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding quick outR1 DH work-order 4 for state #2 | state #2 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x56546b7eebf8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x56546b81fed8 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x56546b81fed8 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x56546b7eebf8 size 128 | suspending state #2 and saving MD | #2 is busy; has a suspended MD | resume sending helper answer for #2 suppresed complete_v1_state_transition() and stole MD | #2 spent 0.0924 milliseconds in resume sending helper answer | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f8640003f28 | crypto helper 6 resuming | crypto helper 6 starting work-order 4 for state #2 | crypto helper 6 doing compute dh (V1 Phase 2 PFS) (quick outR1 DH); request ID 4 | crypto helper 6 finished compute dh (V1 Phase 2 PFS) (quick outR1 DH); request ID 4 time elapsed 0.001026 seconds | (#2) spent 1.03 milliseconds in crypto helper computing work-order 4: quick outR1 DH (pcr) | crypto helper 6 sending results from work-order 4 for state #2 to event queue | scheduling resume sending helper answer for #2 | libevent_malloc: new ptr-libevent@0x7f8634003618 size 128 | crypto helper 6 waiting (nothing to do) | processing resume sending helper answer for #2 | start processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 6 replies to request ID 4 | calling continuation function 0x56546aa07b50 | quick_inI1_outR1_cryptocontinue2 for #2: calculated DH, sending R1 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 1645758573 (0x6218486d) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 72 (0x48) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 2 (0x2) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI f3 84 cf fa | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_T (0x3) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified unconditionally; no alg_info to check against | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | netlink_get_spi: allocated 0xac88167e for esp.0@192.1.2.23 | emitting 4 raw bytes of SPI into ISAKMP Proposal Payload | SPI ac 88 16 7e | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | emitting 24 raw bytes of attributes into ISAKMP Transform Payload (ESP) | attributes 80 03 00 0e 80 04 00 01 80 01 00 01 80 02 70 80 | attributes 80 05 00 02 80 06 00 80 | emitting length of ISAKMP Transform Payload (ESP): 32 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 "TUNNEL-A" #2: responding to Quick Mode proposal {msgid:6218486d} "TUNNEL-A" #2: us: 192.0.2.254/32===192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org] "TUNNEL-A" #2: them: 192.1.2.45<192.1.2.45>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org]===192.0.1.254/32 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | next payload chain: ignoring supplied 'ISAKMP Nonce Payload'.'next payload type' value 4:ISAKMP_NEXT_KE | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Nr into ISAKMP Nonce Payload | Nr 24 73 01 9a d9 3d 5b 5c d2 b8 24 78 47 33 2d a2 | Nr 18 ba 0b 33 bb cd 15 f2 ec d5 89 09 42 e8 24 b6 | emitting length of ISAKMP Nonce Payload: 36 | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value 31 2a 05 f8 77 63 2e e1 7d 0a e1 ca e1 3c 7c 06 | keyex value 1f 48 cd 7a 1b a9 c8 20 10 1e d4 ed a1 2e aa 3e | keyex value 5e 58 c6 8f c3 0c 5e ca 8d b6 81 2a 7f c0 82 1f | keyex value 40 50 87 66 51 38 4b 94 5a a1 34 d7 17 82 e1 22 | keyex value 8f a7 0c 49 60 54 b6 81 fc 7e 17 23 47 cd a4 a5 | keyex value 33 d3 a2 fe 2f 6a 9a c6 b4 e4 d9 81 2d 03 c8 ba | keyex value 4c 1b c6 f8 13 53 2e cc c3 c9 cb f8 82 be ea 1f | keyex value 7b 23 4d f3 8d bb ac d8 f7 73 fe 09 62 96 82 1b | keyex value a6 ca c6 9b 5e b6 50 c2 a8 96 1b ae df 97 28 cf | keyex value db 8e b0 31 6f 10 1b 09 90 c5 51 45 3d bc 79 97 | keyex value 50 f9 3d c1 32 7b 4a ab eb 4a 8f 68 0b e1 09 de | keyex value 02 ec 82 b4 0b e4 d8 21 91 ee 7e 8a ac 17 a5 ba | keyex value 56 e0 07 33 11 b3 82 fa aa 88 27 74 3b 15 68 79 | keyex value 18 48 06 b4 2e fa 07 a8 1e aa 6c fe 91 84 2a e5 | keyex value 0b 57 57 3e 89 ed 03 5e 22 79 1b 50 35 1a 76 28 | keyex value 7b fb 93 5d c4 0c 4a c0 7b 1c b8 51 55 59 cd 89 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of ID body into ISAKMP Identification Payload (IPsec DOI) | ID body c0 00 01 fe | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of ID body into ISAKMP Identification Payload (IPsec DOI) | ID body c0 00 02 fe | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | quick inR1 outI2 HASH(2): | 5e af ae e0 00 eb ab e1 f9 ff 89 28 c4 81 15 77 | 72 e5 07 b9 95 17 6e 36 45 2c 44 b8 11 ab 0f bb | compute_proto_keymat: needed_len (after ESP enc)=16 | compute_proto_keymat: needed_len (after ESP auth)=36 | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-A" unrouted: NULL | install_inbound_ipsec_sa() checking if we can route | could_route called for TUNNEL-A (kind=CK_PERMANENT) | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-A" unrouted: NULL; eroute owner: NULL | routing is easy, or has resolvable near-conflict | checking if this is a replacement state | st=0x56546b8364c8 ost=(nil) st->serialno=#2 ost->serialno=#0 | installing outgoing SA now as refhim=0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-A' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.f384cffa@192.1.2.45 included non-error error | outgoing SA has refhim=0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-A' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.ac88167e@192.1.2.23 included non-error error | priority calculation of connection "TUNNEL-A" is 0xfdfdf | add inbound eroute 192.0.1.254/32:0 --0-> 192.0.2.254/32:0 => tun.10000@192.1.2.23 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | emitting 4 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 444 | finished processing quick inI1 | complete v1 state transition with STF_OK | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #2 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_R0 to state STATE_QUICK_R1 | child state #2: QUICK_R0(established CHILD SA) => QUICK_R1(established CHILD SA) | event_already_set, deleting event | state #2 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x56546b7eebf8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x56546b81fed8 | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 444 bytes for STATE_QUICK_R0 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #2) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 62 18 48 6d 00 00 01 bc 61 22 cc b7 | bf 9a 67 cd 2f 8b c8 33 ab 24 19 6c f4 d9 f1 1d | 50 4e 02 0e b6 5e c5 2a f1 9d 1e d0 6d 35 e7 69 | 71 9c d6 a9 48 72 08 b1 24 17 78 f2 53 d5 7f d5 | d7 50 6f 4b 0d 74 55 45 50 3e e0 31 72 c7 f9 02 | 5f c9 20 e4 ca 33 8b ff cf 35 a3 5e d7 bf 66 2d | 2a d1 c4 2b a0 8b a4 8e fa 94 7f 48 3c e6 8b 65 | 41 ae ef fa 3e 5b 80 7e 27 d5 de 29 94 4a 76 30 | a7 37 2f 18 08 48 a7 06 07 b7 b4 f9 1f 60 c0 bb | c2 86 dd 2e 2c a7 5b c0 ec 15 50 fb f0 77 62 8a | ab 62 55 eb 61 fb 83 f4 cd e5 43 60 b2 d0 c5 83 | 03 a5 10 44 c8 a6 fe 6f 9f 37 ef b1 76 9a 2b 3f | ac 8c 7f 91 59 9c ef 37 1e c3 f5 76 a4 98 74 24 | 76 7f c8 86 e1 66 73 b0 78 9d 3e 7d e5 7d a1 f5 | 43 42 97 07 a5 2f 4e 3d d5 fe e2 4a 91 db 0e b5 | 02 22 a0 f5 ee 7d 35 63 9e 69 6f ea 8c ec 38 ed | 3c 5e f3 1d 28 81 f2 92 32 a8 cc 9b a3 88 5f 62 | a1 39 27 d3 a1 4a 2a d8 17 59 02 07 7e 0e ee 37 | 5f 80 ab 51 db ac 93 e7 f0 61 8f 69 e8 7a 66 6d | fb 68 9d b7 21 dc 68 f5 47 22 fb 84 4d 76 4a 26 | 5a 82 c2 31 68 65 8a e5 2f 39 c1 b7 cb d7 41 9e | 20 7a d8 eb 3c 1d 81 03 ea 7f 81 78 83 60 53 db | ca b7 b9 2a 7c 8d 34 fe 6b 00 c2 5c 7e ac c0 c1 | 6e 99 f2 ea 00 70 86 51 04 93 e2 65 d6 f4 f5 c0 | 4e ba 19 25 6f 30 2c 5a 73 a7 4d 45 65 49 26 80 | da 20 d2 18 0a cc b4 79 5d be 4e 06 90 72 d1 5d | d1 bc 21 57 8e 04 df 0e c1 18 4a 65 | !event_already_set at reschedule | event_schedule: new EVENT_RETRANSMIT-pe@0x56546b81fed8 | inserting event EVENT_RETRANSMIT, timeout in 0.5 seconds for #2 | libevent_malloc: new ptr-libevent@0x56546b824d58 size 128 | #2 STATE_QUICK_R1: retransmits: first event in 0.5 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11182.197725 | pstats #2 ikev1.ipsec established | NAT-T: encaps is 'auto' "TUNNEL-A" #2: STATE_QUICK_R1: sent QR1, inbound IPsec SA installed, expecting QI2 tunnel mode {ESP=>0xf384cffa <0xac88167e xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #2 suppresed complete_v1_state_transition() | #2 spent 1.1 milliseconds in resume sending helper answer | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f8634003618 | spent 0.00502 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 76 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 62 18 48 6d 00 00 00 4c 36 62 2f 59 | 94 2d ab 32 6e 7b f5 1e 36 95 65 d4 25 99 6f 66 | 7c 69 e8 38 02 7f 29 5a 1e 71 e7 07 d3 74 ec be | f2 e0 00 6d 47 75 eb 3f 90 a8 44 4a | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 1645758573 (0x6218486d) | length: 76 (0x4c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: found IKEv1 state #2 in QUICK_R1 (find_state_ikev1) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1633) | #2 is idle | #2 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x100 opt: 0x0 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | removing 12 bytes of padding | quick_inI2 HASH(3): | b6 02 e8 2d bb f2 3b 76 6f c2 a8 85 6e de a3 1c | fc 48 e5 fa cf 64 a3 71 3e a5 f0 ca a8 60 44 9a | received 'quick_inI2' message HASH(3) data ok | install_ipsec_sa() for #2: outbound only | could_route called for TUNNEL-A (kind=CK_PERMANENT) | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-A" unrouted: NULL; eroute owner: NULL | sr for #2: unrouted | route_and_eroute() for proto 0, and source port 0 dest port 0 | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-A" unrouted: NULL; eroute owner: NULL | route_and_eroute with c: TUNNEL-A (next: none) ero:null esr:{(nil)} ro:null rosr:{(nil)} and state: #2 | priority calculation of connection "TUNNEL-A" is 0xfdfdf | eroute_connection add eroute 192.0.2.254/32:0 --0-> 192.0.1.254/32:0 => tun.0@192.1.2.45 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | running updown command "ipsec _updown" for verb up | command executing up-client | executing up-client: PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.254/32' PLUTO_MY_CLIENT_NET='192.0.2.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMIL | popen cmd is 1313 chars long | cmd( 0):PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INT: | cmd( 80):ERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=C: | cmd( 160):A, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libre: | cmd( 240):swan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.254/32' PL: | cmd( 320):UTO_MY_CLIENT_NET='192.0.2.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_: | cmd( 400):PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_: | cmd( 480):PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Te: | cmd( 560):st Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org': | cmd( 640): PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PE: | cmd( 720):ER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLU: | cmd( 800):TO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+E: | cmd( 880):NCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND: | cmd( 960):='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_MY_SOURCEIP='1: | cmd(1040):92.0.2.254' PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INF: | cmd(1120):O='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CON: | cmd(1200):FIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xf384cffa SPI_: | cmd(1280):OUT=0xac88167e ipsec _updown 2>&1: | route_and_eroute: firewall_notified: true | running updown command "ipsec _updown" for verb prepare | command executing prepare-client | executing prepare-client: PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.254/32' PLUTO_MY_CLIENT_NET='192.0.2.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN | popen cmd is 1318 chars long | cmd( 0):PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUT: | cmd( 80):O_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID: | cmd( 160):='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.: | cmd( 240):libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.254/3: | cmd( 320):2' PLUTO_MY_CLIENT_NET='192.0.2.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUT: | cmd( 400):O_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' P: | cmd( 480):LUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, : | cmd( 560):OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan: | cmd( 640):.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLU: | cmd( 720):TO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0: | cmd( 800):' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSA: | cmd( 880):SIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN: | cmd( 960):_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_MY_SOURCE: | cmd(1040):IP='192.0.2.254' PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAI: | cmd(1120):N_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_N: | cmd(1200):M_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xf384cffa: | cmd(1280): SPI_OUT=0xac88167e ipsec _updown 2>&1: | running updown command "ipsec _updown" for verb route | command executing route-client | executing route-client: PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.254/32' PLUTO_MY_CLIENT_NET='192.0.2.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADD | popen cmd is 1316 chars long | cmd( 0):PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_: | cmd( 80):INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID=': | cmd( 160):C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.li: | cmd( 240):breswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.254/32': | cmd( 320): PLUTO_MY_CLIENT_NET='192.0.2.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_: | cmd( 400):MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLU: | cmd( 480):TO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU: | cmd( 560):=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.o: | cmd( 640):rg' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO: | cmd( 720):_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' : | cmd( 800):PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASI: | cmd( 880):G+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_K: | cmd( 960):IND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_MY_SOURCEIP: | cmd(1040):='192.0.2.254' PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_: | cmd(1120):INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_: | cmd(1200):CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xf384cffa S: | cmd(1280):PI_OUT=0xac88167e ipsec _updown 2>&1: "TUNNEL-A" #2: route-client output: Error: Peer netns reference is invalid. "TUNNEL-A" #2: route-client output: Error: Peer netns reference is invalid. "TUNNEL-A" #2: route-client output: Error: Peer netns reference is invalid. | route_and_eroute: instance "TUNNEL-A", setting eroute_owner {spd=0x56546b813738,sr=0x56546b813738} to #2 (was #0) (newest_ipsec_sa=#0) | #1 spent 2.08 milliseconds in install_ipsec_sa() | inI2: instance TUNNEL-A[0], setting IKEv1 newest_ipsec_sa to #2 (was #0) (spd.eroute=#2) cloned from #1 | DPD: dpd_init() called on IPsec SA | DPD: Peer does not support Dead Peer Detection | complete v1 state transition with STF_OK | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #2 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_R1 to state STATE_QUICK_R2 | child state #2: QUICK_R1(established CHILD SA) => QUICK_R2(established CHILD SA) | event_already_set, deleting event | state #2 requesting EVENT_RETRANSMIT to be deleted | #2 STATE_QUICK_R2: retransmits: cleared | libevent_free: release ptr-libevent@0x56546b824d58 | free_event_entry: release EVENT_RETRANSMIT-pe@0x56546b81fed8 | !event_already_set at reschedule | event_schedule: new EVENT_SA_REPLACE-pe@0x56546b81fed8 | inserting event EVENT_SA_REPLACE, timeout in 28799 seconds for #2 | libevent_malloc: new ptr-libevent@0x7f8634003618 size 128 | pstats #2 ikev1.ipsec established | NAT-T: encaps is 'auto' "TUNNEL-A" #2: STATE_QUICK_R2: IPsec SA established tunnel mode {ESP=>0xf384cffa <0xac88167e xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | #2 spent 2.16 milliseconds in process_packet_tail() | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 2.33 milliseconds in comm_handle_cb() reading and processing packet | kernel_process_msg_cb process netlink message | netlink_get: XFRM_MSG_EXPIRE message | spent 0.00731 milliseconds in kernel message | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00353 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.0021 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00207 milliseconds in signal handler PLUTO_SIGCHLD | spent 0.00257 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 476 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 38 f9 05 49 00 00 01 dc 2a e0 e1 97 | 24 90 9a 43 5e f9 b3 75 74 62 24 a4 47 da 76 c4 | 74 1a c1 b8 17 9b 1d 09 f3 6b 16 c3 43 1d 09 87 | 2f b4 9c 81 99 35 fb 4c 5f 0e 42 06 c4 a3 cc cf | fa 89 e5 d4 21 05 c1 37 7e 5f eb 65 75 6c ba 61 | da 16 ff f4 87 c6 c2 6a ff b4 73 79 dc 8b bb 0b | 61 44 fe c0 23 bc 6e cc 84 86 23 50 4d 43 98 b5 | a7 29 69 27 04 ad e5 60 35 a7 f8 5b d8 29 24 56 | 99 fa 4a e6 84 26 b2 eb fc 22 fe 3e a3 6f 09 63 | d1 00 a6 9e ea 4e b2 53 db 67 1e 94 d0 d4 34 77 | 91 10 33 29 1d b9 92 d0 b3 22 09 d2 41 53 6d 66 | 5a 92 f1 cf ed 6b 31 ab db 35 f0 0a ca e9 b5 5d | 38 85 14 12 69 95 49 4a d2 aa 33 75 49 9d de 45 | be bf 3b 12 6a aa c6 79 87 fd 60 de 2b 88 f6 57 | b0 67 50 f1 86 5a 3d 30 18 17 ff 3e df 35 e4 6d | 6f 84 24 07 aa 83 ba d5 db f0 77 a0 6f e7 c9 85 | c0 48 1a 5e 9b 50 15 d2 86 76 e3 91 2d 3d c4 09 | 96 65 29 a6 71 bd b8 3b 8d 53 c7 24 98 95 51 b1 | 6a 92 68 c3 2d 20 bd 6e 09 16 c7 fe 40 b7 78 c2 | 01 8f cb 22 20 75 14 bb 22 44 33 49 75 6a 44 f7 | 60 f4 9d 4d 68 d3 79 29 1d 57 92 20 57 a6 dd ac | 65 43 a6 ff e2 e9 9f 06 51 f4 04 7a 76 85 7e 75 | 9d fe df f0 8e 91 6b 3b 22 8a 87 e0 84 71 b1 e6 | 7a 63 6e ff eb a6 60 e3 5a a6 64 73 60 ec 60 27 | c5 b0 f9 f6 8e 26 54 4c 2c 8a c2 cf 57 65 93 0d | e8 d2 01 0b 93 db 98 90 23 98 b6 eb 80 d1 1b 43 | a2 c3 7f c5 42 37 c9 f1 c7 3c 91 5b c4 f5 d7 40 | 43 0e be ae 6d 15 f4 1c f9 ee d4 43 b0 5b 01 b8 | 3c e3 de 71 26 4b 19 45 f3 6a ff 21 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 955843913 (0x38f90549) | length: 476 (0x1dc) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: IKEv1 state not found (find_state_ikev1) | State DB: found IKEv1 state #1 in MAIN_R3 (find_state_ikev1) | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1607) | #1 is idle | #1 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x502 opt: 0x200030 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_SA (0x1) | length: 36 (0x24) | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x402 opt: 0x200030 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 84 (0x54) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x200030 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | length: 36 (0x24) | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | length: 260 (0x104) | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 01 fe | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 02 f4 | removing 8 bytes of padding | quick_inI1_outR1 HASH(1): | 8e 75 8b 1b a4 5c 71 95 2d 11 8e 2e 5a c7 0e 29 | 8c 9f 5a b5 a2 05 3e 2a 04 8b d2 7f 65 ae 28 e0 | received 'quick_inI1_outR1' message HASH(1) data ok | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 01 fe | peer client is 192.0.1.254/32 | peer client protocol/port is 0/0 | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 02 f4 | our client is 192.0.2.244/32 | our client protocol/port is 0/0 "TUNNEL-C" #1: the peer proposed: 192.0.2.244/32:0/0 -> 192.0.1.254/32:0/0 | find_client_connection starting with TUNNEL-C | looking for 192.0.2.244/32:0/0 -> 192.0.1.254/32:0/0 | concrete checking against sr#0 192.0.2.234/32 -> 192.0.1.254/32 | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | fc_try trying TUNNEL-C:192.0.2.244/32:0/0 -> 192.0.1.254/32:0/0 vs TUNNEL-C:192.0.2.234/32:0/0 -> 192.0.1.254/32:0/0 | our client (192.0.2.234/32) not in our_net (192.0.2.244/32) | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | fc_try trying TUNNEL-C:192.0.2.244/32:0/0 -> 192.0.1.254/32:0/0 vs TUNNEL-B:192.0.2.244/32:0/0 -> 192.0.1.254/32:0/0 | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | fc_try trying TUNNEL-C:192.0.2.244/32:0/0 -> 192.0.1.254/32:0/0 vs TUNNEL-A:192.0.2.254/32:0/0 -> 192.0.1.254/32:0/0 | our client (192.0.2.254/32) not in our_net (192.0.2.244/32) | fc_try concluding with TUNNEL-B [128] | fc_try TUNNEL-C gives TUNNEL-B | concluding with d = TUNNEL-B | using connection "TUNNEL-B" | client wildcard: no port wildcard: no virtual: no | creating state object #3 at 0x56546b825308 | State DB: adding IKEv1 state #3 in UNDEFINED | pstats #3 ikev1.ipsec started | duplicating state object #1 "TUNNEL-C" as #3 for IPSEC SA | #3 setting local endpoint to 192.1.2.23:500 from #1.st_localport (in duplicate_state() at state.c:1484) | in connection_discard for connection TUNNEL-C | start processing: connection "TUNNEL-B" (BACKGROUND) (in quick_inI1_outR1_tail() at ikev1_quick.c:1286) | suspend processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in quick_inI1_outR1_tail() at ikev1_quick.c:1295) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in quick_inI1_outR1_tail() at ikev1_quick.c:1295) | child state #3: UNDEFINED(ignore) => QUICK_R0(established CHILD SA) | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 72 (0x48) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 2 (0x2) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI e9 31 61 bd | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_T (0x3) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified unconditionally; no alg_info to check against | adding quick_outI1 KE work-order 5 for state #3 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f8640004218 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #3 | libevent_malloc: new ptr-libevent@0x56546b7eebf8 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #3 and saving MD | #3 is busy; has a suspended MD | #1 spent 0.167 milliseconds in process_packet_tail() | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in process_md() at demux.c:382) | resume processing: connection "TUNNEL-B" (in process_md() at demux.c:382) | stop processing: connection "TUNNEL-B" (in process_md() at demux.c:383) | spent 0.369 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 2 resuming | crypto helper 2 starting work-order 5 for state #3 | crypto helper 2 doing build KE and nonce (quick_outI1 KE); request ID 5 | crypto helper 2 finished build KE and nonce (quick_outI1 KE); request ID 5 time elapsed 0.000571 seconds | (#3) spent 0.574 milliseconds in crypto helper computing work-order 5: quick_outI1 KE (pcr) | crypto helper 2 sending results from work-order 5 for state #3 to event queue | scheduling resume sending helper answer for #3 | libevent_malloc: new ptr-libevent@0x7f8638002888 size 128 | crypto helper 2 waiting (nothing to do) | processing resume sending helper answer for #3 | start processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 2 replies to request ID 5 | calling continuation function 0x56546aa07b50 | quick_inI1_outR1_cryptocontinue1 for #3: calculated ke+nonce, calculating DH | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding quick outR1 DH work-order 6 for state #3 | state #3 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x56546b7eebf8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f8640004218 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f8640004218 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #3 | libevent_malloc: new ptr-libevent@0x56546b7eebf8 size 128 | suspending state #3 and saving MD | #3 is busy; has a suspended MD | resume sending helper answer for #3 suppresed complete_v1_state_transition() and stole MD | #3 spent 0.0484 milliseconds in resume sending helper answer | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f8638002888 | crypto helper 5 resuming | crypto helper 5 starting work-order 6 for state #3 | crypto helper 5 doing compute dh (V1 Phase 2 PFS) (quick outR1 DH); request ID 6 | crypto helper 5 finished compute dh (V1 Phase 2 PFS) (quick outR1 DH); request ID 6 time elapsed 0.000518 seconds | (#3) spent 0.521 milliseconds in crypto helper computing work-order 6: quick outR1 DH (pcr) | crypto helper 5 sending results from work-order 6 for state #3 to event queue | scheduling resume sending helper answer for #3 | libevent_malloc: new ptr-libevent@0x7f862c001f78 size 128 | crypto helper 5 waiting (nothing to do) | processing resume sending helper answer for #3 | start processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 5 replies to request ID 6 | calling continuation function 0x56546aa07b50 | quick_inI1_outR1_cryptocontinue2 for #3: calculated DH, sending R1 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 955843913 (0x38f90549) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 72 (0x48) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 2 (0x2) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI e9 31 61 bd | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_T (0x3) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified unconditionally; no alg_info to check against | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | netlink_get_spi: allocated 0x2310b106 for esp.0@192.1.2.23 | emitting 4 raw bytes of SPI into ISAKMP Proposal Payload | SPI 23 10 b1 06 | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | emitting 24 raw bytes of attributes into ISAKMP Transform Payload (ESP) | attributes 80 03 00 0e 80 04 00 01 80 01 00 01 80 02 70 80 | attributes 80 05 00 02 80 06 00 80 | emitting length of ISAKMP Transform Payload (ESP): 32 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 "TUNNEL-B" #3: responding to Quick Mode proposal {msgid:38f90549} "TUNNEL-B" #3: us: 192.0.2.244/32===192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org] "TUNNEL-B" #3: them: 192.1.2.45<192.1.2.45>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org]===192.0.1.254/32 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | next payload chain: ignoring supplied 'ISAKMP Nonce Payload'.'next payload type' value 4:ISAKMP_NEXT_KE | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Nr into ISAKMP Nonce Payload | Nr 1d 60 51 73 27 f2 63 33 40 87 db d4 d4 5c 28 6c | Nr 63 56 bc ce c7 a3 03 11 86 13 86 d8 f1 83 1c ce | emitting length of ISAKMP Nonce Payload: 36 | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value 90 64 66 d6 c9 90 03 92 c6 a0 cc 98 b5 15 f8 c9 | keyex value 95 e9 aa 37 a2 83 f6 d3 4d 01 d0 9f 84 b0 68 76 | keyex value da ea 92 f0 01 41 fc dc a4 9a 7e 60 53 72 1e 06 | keyex value 08 81 06 6f b2 54 92 d7 e7 13 6d dc ba c7 2f 60 | keyex value 82 78 7b 10 b2 bb 07 cf 8e fc 20 26 5b d8 ff c6 | keyex value b0 03 6e 87 af 59 c5 eb ed 51 c8 f6 ce 98 75 ec | keyex value 90 65 d4 e3 56 b3 1f fa b5 9f da 12 7d e9 88 98 | keyex value 6b 42 63 76 d8 cc 21 dc 55 44 1b 2b 7d 0d 21 40 | keyex value 37 67 18 14 2f ea 57 f5 e6 c1 3c a0 05 b9 78 b4 | keyex value 38 2b 76 22 01 14 09 d8 2a 20 0a b7 e6 d8 ca a8 | keyex value 3b 27 ce 2c 5b 74 27 30 0f 7e 2e 63 28 b7 f8 38 | keyex value 13 c0 e8 6b f4 b7 40 a2 d6 30 3c 8d 4c 99 66 6c | keyex value 48 f8 07 df 94 f6 37 aa bc 4c 5c 61 6c a7 15 b5 | keyex value 52 95 29 8c 99 9e fd 60 48 c4 bd 7c 70 64 ec d2 | keyex value ce 73 da fe 2e ff e5 65 2f 7a 8c 5d 89 38 13 bb | keyex value d7 75 c6 09 2f fc a0 ca 4f b3 f6 33 8b 86 d9 54 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of ID body into ISAKMP Identification Payload (IPsec DOI) | ID body c0 00 01 fe | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of ID body into ISAKMP Identification Payload (IPsec DOI) | ID body c0 00 02 f4 | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | quick inR1 outI2 HASH(2): | e2 2c 9f 13 e4 b4 3e 23 ab 5e e2 55 62 f3 f5 52 | ab ef 55 6b ab cb ad d7 b5 23 38 9c 3e 70 c1 92 | compute_proto_keymat: needed_len (after ESP enc)=16 | compute_proto_keymat: needed_len (after ESP auth)=36 | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-B" unrouted: "TUNNEL-A" erouted | install_inbound_ipsec_sa() checking if we can route | could_route called for TUNNEL-B (kind=CK_PERMANENT) | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-B" unrouted: "TUNNEL-A" erouted; eroute owner: NULL | routing is easy, or has resolvable near-conflict | checking if this is a replacement state | st=0x56546b825308 ost=(nil) st->serialno=#3 ost->serialno=#0 | installing outgoing SA now as refhim=0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-B' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.e93161bd@192.1.2.45 included non-error error | outgoing SA has refhim=0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-B' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.2310b106@192.1.2.23 included non-error error | priority calculation of connection "TUNNEL-B" is 0xfdfdf | add inbound eroute 192.0.1.254/32:0 --0-> 192.0.2.244/32:0 => tun.10000@192.1.2.23 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | emitting 4 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 444 | finished processing quick inI1 | complete v1 state transition with STF_OK | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #3 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_R0 to state STATE_QUICK_R1 | child state #3: QUICK_R0(established CHILD SA) => QUICK_R1(established CHILD SA) | event_already_set, deleting event | state #3 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x56546b7eebf8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f8640004218 | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 444 bytes for STATE_QUICK_R0 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #3) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 38 f9 05 49 00 00 01 bc d3 40 62 11 | 6b 5e 72 88 9a ce 00 e1 0a 75 b6 77 5d 00 86 f2 | 03 e6 88 1b 17 a9 99 c2 df 68 b5 88 f7 91 ef 5e | 59 37 a9 a6 fb 11 2a 5a c0 2d 9b d2 74 8a 66 5c | 85 b7 e3 10 fb 0c e2 21 58 89 71 ee 65 fb bb 0a | aa 6b 84 28 e0 0d b0 93 06 63 24 65 36 af ed 88 | 6d b6 1b 39 a9 e7 aa af 27 3f b1 b0 34 8a 39 7a | 98 3c f0 aa f3 8d 17 05 4c 16 9b d3 50 13 10 c6 | 09 84 1e 96 3f bc a5 05 8f 0f c4 fb a4 66 70 37 | ae 42 0e 6d 47 f9 11 1c a6 3b 09 ca fd a6 f5 2d | fc ed 03 cd 1c 29 ac f4 6b 40 3d e9 2e 9e de a8 | 17 bc 7d e2 72 15 c5 7c 6d bb 48 5d 91 c5 f5 07 | f0 ff bd 85 d7 ad 38 bd e6 2f 41 97 9d fd 09 b2 | 91 7d 13 7c 1d fd cd 32 24 39 ac 2a 9f 94 46 e4 | d3 6c 66 0b 20 cd 9e 4f a8 07 5f 87 6d b5 3e 1c | 8a e3 55 0f 2f 88 45 34 b8 6d 5d 2b 59 6e 36 5a | 68 a9 37 de 42 9f 75 f4 2d 7a 0a 31 0b 57 6b 0b | 7d aa 45 16 01 4f ff 6c 30 40 6d 89 a3 d2 96 fd | 46 c8 6f b4 f9 12 48 cb a7 4f 1d 59 00 58 bc c1 | bf 59 6d ca 89 60 a7 87 a5 aa 2c 34 ba ea 15 0b | 2c fe 45 51 0c 2f c8 c0 92 51 1f 55 6f 1d 0c 00 | 19 ec 05 d2 cb 84 63 4c 0b fc 2c 35 63 b4 83 44 | d3 57 e1 93 b7 2e 2c 59 ec 3f 79 c3 d0 9e 77 da | b6 29 1b b2 91 83 57 ea bc 5f d6 eb 51 81 20 cf | eb b3 3f cc 6c 8a 40 d6 79 6e 3f 81 05 36 ce d9 | de ec 41 d7 72 bc 95 59 14 4a f1 09 e1 c0 b9 11 | 31 79 ba 5c a4 3b 4b 65 f9 1e 24 06 | !event_already_set at reschedule | event_schedule: new EVENT_RETRANSMIT-pe@0x7f8640004218 | inserting event EVENT_RETRANSMIT, timeout in 0.5 seconds for #3 | libevent_malloc: new ptr-libevent@0x7f8638002888 size 128 | #3 STATE_QUICK_R1: retransmits: first event in 0.5 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11182.311334 | pstats #3 ikev1.ipsec established | NAT-T: encaps is 'auto' "TUNNEL-B" #3: STATE_QUICK_R1: sent QR1, inbound IPsec SA installed, expecting QI2 tunnel mode {ESP=>0xe93161bd <0x2310b106 xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #3 suppresed complete_v1_state_transition() | #3 spent 0.744 milliseconds in resume sending helper answer | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f862c001f78 | spent 0.0028 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 76 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 38 f9 05 49 00 00 00 4c 8b b5 47 88 | f3 dd fd 66 8f a9 dc 7c be 47 20 86 06 29 00 ca | 96 b1 d1 9b 32 55 a1 9f 58 3e 95 18 08 08 c7 9d | 5a ef dd 10 e2 de 15 f8 90 9d b7 9e | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 955843913 (0x38f90549) | length: 76 (0x4c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: found IKEv1 state #3 in QUICK_R1 (find_state_ikev1) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1633) | #3 is idle | #3 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x100 opt: 0x0 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | removing 12 bytes of padding | quick_inI2 HASH(3): | ae ad de 7a a9 da 1f d5 4b 84 5c d3 c8 f1 68 ad | 37 af e2 9a 91 ab ad 38 07 bd a3 3c ac 14 ce 8d | received 'quick_inI2' message HASH(3) data ok | install_ipsec_sa() for #3: outbound only | could_route called for TUNNEL-B (kind=CK_PERMANENT) | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-B" unrouted: "TUNNEL-A" erouted; eroute owner: NULL | sr for #3: unrouted | route_and_eroute() for proto 0, and source port 0 dest port 0 | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-B" unrouted: "TUNNEL-A" erouted; eroute owner: NULL | route_and_eroute with c: TUNNEL-B (next: none) ero:null esr:{(nil)} ro:TUNNEL-A rosr:{0x56546b813738} and state: #3 | priority calculation of connection "TUNNEL-B" is 0xfdfdf | eroute_connection add eroute 192.0.2.244/32:0 --0-> 192.0.1.254/32:0 => tun.0@192.1.2.45 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | running updown command "ipsec _updown" for verb up | command executing up-client | executing up-client: PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.244/32' PLUTO_MY_CLIENT_NET='192.0.2.244' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMIL | popen cmd is 1313 chars long | cmd( 0):PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_INT: | cmd( 80):ERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=C: | cmd( 160):A, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libre: | cmd( 240):swan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.244/32' PL: | cmd( 320):UTO_MY_CLIENT_NET='192.0.2.244' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_: | cmd( 400):PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_: | cmd( 480):PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Te: | cmd( 560):st Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org': | cmd( 640): PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PE: | cmd( 720):ER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLU: | cmd( 800):TO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+E: | cmd( 880):NCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND: | cmd( 960):='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_MY_SOURCEIP='1: | cmd(1040):92.0.2.244' PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INF: | cmd(1120):O='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CON: | cmd(1200):FIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xe93161bd SPI_: | cmd(1280):OUT=0x2310b106 ipsec _updown 2>&1: | route_and_eroute: firewall_notified: true | route_and_eroute: instance "TUNNEL-B", setting eroute_owner {spd=0x56546b818d28,sr=0x56546b818d28} to #3 (was #0) (newest_ipsec_sa=#0) | #1 spent 0.618 milliseconds in install_ipsec_sa() | inI2: instance TUNNEL-B[0], setting IKEv1 newest_ipsec_sa to #3 (was #0) (spd.eroute=#3) cloned from #1 | DPD: dpd_init() called on IPsec SA | DPD: Peer does not support Dead Peer Detection | complete v1 state transition with STF_OK | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #3 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_R1 to state STATE_QUICK_R2 | child state #3: QUICK_R1(established CHILD SA) => QUICK_R2(established CHILD SA) | event_already_set, deleting event | state #3 requesting EVENT_RETRANSMIT to be deleted | #3 STATE_QUICK_R2: retransmits: cleared | libevent_free: release ptr-libevent@0x7f8638002888 | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f8640004218 | !event_already_set at reschedule | event_schedule: new EVENT_SA_REPLACE-pe@0x7f8640004218 | inserting event EVENT_SA_REPLACE, timeout in 28799 seconds for #3 | libevent_malloc: new ptr-libevent@0x7f862c001f78 size 128 | pstats #3 ikev1.ipsec established | NAT-T: encaps is 'auto' "TUNNEL-B" #3: STATE_QUICK_R2: IPsec SA established tunnel mode {ESP=>0xe93161bd <0x2310b106 xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | #3 spent 0.686 milliseconds in process_packet_tail() | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.814 milliseconds in comm_handle_cb() reading and processing packet | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00311 milliseconds in signal handler PLUTO_SIGCHLD | spent 0.00526 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 476 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 af 95 83 06 00 00 01 dc ba 77 0e 5c | f4 5c 31 5e ac 7c 4c 33 7f 07 f6 63 47 48 7a 2d | fc de f0 40 22 31 c5 f7 cd 25 ce ab 22 3d 0e e8 | c6 ec 28 2c 42 5d 67 4b 5a d2 46 84 cd f9 83 57 | cf c6 6a 92 d7 8a ba 0b f9 da 0f 5b b9 93 2b ad | 88 ae 62 e1 33 cd 9c 32 91 64 4b 47 70 77 7d 0c | 95 40 ef 14 56 25 56 3b 46 79 d2 71 e9 1a c5 6d | 6b 83 17 49 ca 0f 14 ec 80 d0 a5 12 12 9e 40 bc | 2e bc b5 51 8f 1e 3f 0c 8c 26 b5 bb 4a 71 2c 86 | 90 19 9f 19 25 ec bb b3 8a 8b d0 49 83 91 a6 5b | 11 28 ef bb c9 4f 3d 3e 8f aa 8a f8 d2 b8 e0 b2 | e6 4d 58 54 10 41 5c e6 f9 c9 a3 32 4d fe 26 5e | 51 f3 c9 1d 76 5a 46 72 2c 22 26 6e df 0b 77 8d | a4 87 6f a5 91 a7 d2 0a 43 79 53 f4 f2 db 14 95 | d8 76 08 12 f6 08 b0 3d b8 5f 25 09 fa e6 a0 6d | 96 28 dd 6e aa 45 f4 50 bf 0f 3c 61 4c c4 16 f9 | ec b0 52 2d bc 16 a3 fc 37 97 46 bf d8 9a 65 02 | 6a 85 5e 98 14 59 9e ff d6 20 b1 cf e0 d7 5e e0 | e0 9e a9 a7 de 6f 7a 21 62 af cf 47 08 fe 26 65 | d4 e8 1c 1a e3 f9 77 b5 ed f7 89 8f 07 2b 95 3f | 9f 65 04 96 79 87 c0 3c 3c dd 45 d4 68 de c8 17 | eb f4 34 1d d3 c5 8f 7b 04 a5 52 c5 26 6d 23 4b | fd 3a 5a da fb 7d ac 8d 4c 24 13 6f 0f 2e 3b 93 | 2f a5 b4 bf 40 df 7a 9c f4 e8 3e e0 b3 3f 99 9d | f0 10 df b7 a2 a6 44 a0 e8 87 84 74 a0 01 02 36 | fe 81 11 0e 5d 50 e4 74 4c 5b 47 47 9b e0 1c c8 | 9c 69 11 d3 75 63 91 4b 70 76 33 c0 47 69 ef da | a5 28 be 2b d2 1a 89 48 ed 29 d0 39 57 0e 59 a2 | 83 3a d6 5f 7e 88 e7 2a 53 5b 14 68 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 2945811206 (0xaf958306) | length: 476 (0x1dc) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: IKEv1 state not found (find_state_ikev1) | State DB: found IKEv1 state #1 in MAIN_R3 (find_state_ikev1) | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1607) | #1 is idle | #1 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x502 opt: 0x200030 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_SA (0x1) | length: 36 (0x24) | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x402 opt: 0x200030 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 84 (0x54) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x200030 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | length: 36 (0x24) | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | length: 260 (0x104) | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 01 fe | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 02 ea | removing 8 bytes of padding | quick_inI1_outR1 HASH(1): | b2 0f c5 e3 9e 1a a3 8a 55 ae ee 98 fe 16 e9 94 | d7 7a c2 80 d1 4a e0 55 ce e4 12 dc 94 27 1d db | received 'quick_inI1_outR1' message HASH(1) data ok | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 01 fe | peer client is 192.0.1.254/32 | peer client protocol/port is 0/0 | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 02 ea | our client is 192.0.2.234/32 | our client protocol/port is 0/0 "TUNNEL-C" #1: the peer proposed: 192.0.2.234/32:0/0 -> 192.0.1.254/32:0/0 | find_client_connection starting with TUNNEL-C | looking for 192.0.2.234/32:0/0 -> 192.0.1.254/32:0/0 | concrete checking against sr#0 192.0.2.234/32 -> 192.0.1.254/32 | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | fc_try trying TUNNEL-C:192.0.2.234/32:0/0 -> 192.0.1.254/32:0/0 vs TUNNEL-C:192.0.2.234/32:0/0 -> 192.0.1.254/32:0/0 | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | fc_try trying TUNNEL-C:192.0.2.234/32:0/0 -> 192.0.1.254/32:0/0 vs TUNNEL-B:192.0.2.244/32:0/0 -> 192.0.1.254/32:0/0 | our client (192.0.2.244/32) not in our_net (192.0.2.234/32) | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org | results matched | fc_try trying TUNNEL-C:192.0.2.234/32:0/0 -> 192.0.1.254/32:0/0 vs TUNNEL-A:192.0.2.254/32:0/0 -> 192.0.1.254/32:0/0 | our client (192.0.2.254/32) not in our_net (192.0.2.234/32) | fc_try concluding with TUNNEL-C [129] | fc_try TUNNEL-C gives TUNNEL-C | concluding with d = TUNNEL-C | client wildcard: no port wildcard: no virtual: no | creating state object #4 at 0x56546b838188 | State DB: adding IKEv1 state #4 in UNDEFINED | pstats #4 ikev1.ipsec started | duplicating state object #1 "TUNNEL-C" as #4 for IPSEC SA | #4 setting local endpoint to 192.1.2.23:500 from #1.st_localport (in duplicate_state() at state.c:1484) | suspend processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in quick_inI1_outR1_tail() at ikev1_quick.c:1295) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in quick_inI1_outR1_tail() at ikev1_quick.c:1295) | child state #4: UNDEFINED(ignore) => QUICK_R0(established CHILD SA) | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 72 (0x48) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 2 (0x2) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI 26 05 d6 2c | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_T (0x3) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified unconditionally; no alg_info to check against | adding quick_outI1 KE work-order 7 for state #4 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f8638002b78 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #4 | libevent_malloc: new ptr-libevent@0x56546b7eebf8 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #4 and saving MD | #4 is busy; has a suspended MD | crypto helper 4 resuming | crypto helper 4 starting work-order 7 for state #4 | #1 spent 0.423 milliseconds in process_packet_tail() | crypto helper 4 doing build KE and nonce (quick_outI1 KE); request ID 7 | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.859 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 4 finished build KE and nonce (quick_outI1 KE); request ID 7 time elapsed 0.001328 seconds | (#4) spent 1.34 milliseconds in crypto helper computing work-order 7: quick_outI1 KE (pcr) | crypto helper 4 sending results from work-order 7 for state #4 to event queue | scheduling resume sending helper answer for #4 | libevent_malloc: new ptr-libevent@0x7f8630002888 size 128 | crypto helper 4 waiting (nothing to do) | processing resume sending helper answer for #4 | start processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 4 replies to request ID 7 | calling continuation function 0x56546aa07b50 | quick_inI1_outR1_cryptocontinue1 for #4: calculated ke+nonce, calculating DH | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding quick outR1 DH work-order 8 for state #4 | state #4 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x56546b7eebf8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f8638002b78 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f8638002b78 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #4 | libevent_malloc: new ptr-libevent@0x56546b7eebf8 size 128 | suspending state #4 and saving MD | #4 is busy; has a suspended MD | resume sending helper answer for #4 suppresed complete_v1_state_transition() and stole MD | #4 spent 0.115 milliseconds in resume sending helper answer | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f8630002888 | crypto helper 0 resuming | crypto helper 0 starting work-order 8 for state #4 | crypto helper 0 doing compute dh (V1 Phase 2 PFS) (quick outR1 DH); request ID 8 | crypto helper 0 finished compute dh (V1 Phase 2 PFS) (quick outR1 DH); request ID 8 time elapsed 0.001258 seconds | (#4) spent 1.27 milliseconds in crypto helper computing work-order 8: quick outR1 DH (pcr) | crypto helper 0 sending results from work-order 8 for state #4 to event queue | scheduling resume sending helper answer for #4 | libevent_malloc: new ptr-libevent@0x7f86440027d8 size 128 | crypto helper 0 waiting (nothing to do) | processing resume sending helper answer for #4 | start processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 0 replies to request ID 8 | calling continuation function 0x56546aa07b50 | quick_inI1_outR1_cryptocontinue2 for #4: calculated DH, sending R1 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 2945811206 (0xaf958306) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 72 (0x48) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 2 (0x2) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI 26 05 d6 2c | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_T (0x3) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified unconditionally; no alg_info to check against | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | netlink_get_spi: allocated 0x58b85bc4 for esp.0@192.1.2.23 | emitting 4 raw bytes of SPI into ISAKMP Proposal Payload | SPI 58 b8 5b c4 | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | emitting 24 raw bytes of attributes into ISAKMP Transform Payload (ESP) | attributes 80 03 00 0e 80 04 00 01 80 01 00 01 80 02 70 80 | attributes 80 05 00 02 80 06 00 80 | emitting length of ISAKMP Transform Payload (ESP): 32 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 "TUNNEL-C" #4: responding to Quick Mode proposal {msgid:af958306} "TUNNEL-C" #4: us: 192.0.2.234/32===192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org] "TUNNEL-C" #4: them: 192.1.2.45<192.1.2.45>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org]===192.0.1.254/32 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | next payload chain: ignoring supplied 'ISAKMP Nonce Payload'.'next payload type' value 4:ISAKMP_NEXT_KE | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Nr into ISAKMP Nonce Payload | Nr e8 28 3b 82 3c 06 53 c5 06 1a 84 c5 80 0c 16 b2 | Nr 2a 01 0b c1 8e cb b0 79 c8 4a 98 1d 95 6e 7c d7 | emitting length of ISAKMP Nonce Payload: 36 | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value b7 a8 6c cf 2b d4 30 33 fe 51 b0 e0 bd 58 fd 57 | keyex value 18 0a 9e 23 45 90 c3 84 6d 21 d1 b8 87 d3 db c1 | keyex value 9f 50 e7 44 e9 df dd 47 b3 25 5e 7d 73 46 88 f2 | keyex value 21 a3 6b 63 a6 d0 6e 2b ba 9e 16 b7 35 13 f9 d1 | keyex value 6c 96 c6 6d 45 05 e1 fa 95 6e ba ee 8e a2 8a 6e | keyex value b7 b9 c6 58 f9 61 21 7a d8 52 6e c6 94 1f ce 93 | keyex value 9b 84 bb a9 c4 65 4d 37 fe 5f 8d 08 e3 e0 a3 15 | keyex value a9 ca d5 51 af 05 be bb dd 53 fb 7b dc 48 a1 a4 | keyex value 42 3f 69 43 11 80 fc 8e b5 af 2c a4 99 33 ee 27 | keyex value cb 41 d8 03 fd 3c f7 a5 da be 3c 6d be 72 0f d5 | keyex value 8e 70 05 af c1 ee b0 5d c0 e6 aa b9 56 21 ad 7c | keyex value 42 04 79 3e 03 68 33 81 d2 6f 65 3d e2 a2 8b 6c | keyex value 3f 69 41 4a a0 51 1c 1a bf 34 1f 53 04 a6 c4 bb | keyex value 62 84 97 bf d4 f0 2c f6 8c af bd bb d8 85 80 a4 | keyex value b7 77 81 cb 07 75 0c 32 6b d4 09 7b dd 51 f4 6d | keyex value 10 49 42 4f d9 a7 95 92 35 1c cd b7 b7 3c 4c 67 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of ID body into ISAKMP Identification Payload (IPsec DOI) | ID body c0 00 01 fe | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of ID body into ISAKMP Identification Payload (IPsec DOI) | ID body c0 00 02 ea | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | quick inR1 outI2 HASH(2): | c2 e6 4b 4b 06 45 46 62 0d f5 28 7c c4 6f fb c0 | a4 ea f6 7d b5 38 e3 76 4a 93 3f f8 80 a6 82 0f | compute_proto_keymat: needed_len (after ESP enc)=16 | compute_proto_keymat: needed_len (after ESP auth)=36 | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-C" unrouted: "TUNNEL-B" erouted | install_inbound_ipsec_sa() checking if we can route | could_route called for TUNNEL-C (kind=CK_PERMANENT) | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-C" unrouted: "TUNNEL-B" erouted; eroute owner: NULL | routing is easy, or has resolvable near-conflict | checking if this is a replacement state | st=0x56546b838188 ost=(nil) st->serialno=#4 ost->serialno=#0 | installing outgoing SA now as refhim=0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-C' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.2605d62c@192.1.2.45 included non-error error | outgoing SA has refhim=0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-C' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.58b85bc4@192.1.2.23 included non-error error | priority calculation of connection "TUNNEL-C" is 0xfdfdf | add inbound eroute 192.0.1.254/32:0 --0-> 192.0.2.234/32:0 => tun.10000@192.1.2.23 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | emitting 4 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 444 | finished processing quick inI1 | complete v1 state transition with STF_OK | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #4 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_R0 to state STATE_QUICK_R1 | child state #4: QUICK_R0(established CHILD SA) => QUICK_R1(established CHILD SA) | event_already_set, deleting event | state #4 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x56546b7eebf8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f8638002b78 | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 444 bytes for STATE_QUICK_R0 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #4) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 af 95 83 06 00 00 01 bc 81 05 12 11 | 70 6d 7a ad 63 67 b1 c6 46 84 15 a5 a4 d7 80 e4 | 0e 72 d6 b4 24 71 2d 9b d5 53 59 af 26 a2 14 cd | 6e db 51 88 db b6 f5 c3 33 3e 2c d3 7b 6e 9b 0d | 95 b8 e0 0b 57 26 7d d3 ad 21 19 0f ae 99 f5 48 | a6 f4 19 7a 89 ed e4 dc 70 b2 d8 30 df 87 0f 70 | 37 58 ad 30 3b 3b 8c 05 c2 25 c9 68 5c 81 cc 91 | 77 63 aa 23 e5 24 ad 1e cf e6 6a 62 80 be 89 fb | 71 23 15 8b 37 a5 a1 35 6b 44 ad 94 28 79 73 16 | 7a 3c aa 01 1c ef 03 69 8f 56 b2 9b 9d bd 77 7b | 9b 85 fc 36 ee 1e 52 08 42 bd 5e a6 94 9e 75 28 | c0 27 d1 3c 5a 95 5d 07 2c ca 83 5d e2 59 d3 41 | 88 01 8b e2 00 82 8f 3c 63 b9 a9 3a aa 4f 3f be | a4 8f b9 7c 82 f9 29 af 0b 26 1e 2f 17 b9 45 1b | 60 ba b7 6a c1 cc 23 75 48 d3 30 ad e9 b3 24 cf | 69 c8 4d 8f 4a 53 ae d3 21 37 3c 15 94 62 fd a3 | 70 81 d4 09 4c d1 7e 6f c3 05 d0 40 33 e5 de 4d | bb da 6e 37 92 97 3d be 9f 39 6d f6 ab 22 4a 90 | c8 c7 af 9e 69 16 be 82 ca cc b6 27 45 40 0b 80 | 50 59 60 9c c6 77 f5 bf a2 7a 47 b2 e9 46 b0 e5 | 2b 16 51 13 2f 8b f5 4f 5a 03 85 d0 c8 44 43 0f | 6b b2 71 fe 36 d2 4d 89 51 96 e4 08 53 0c 8c d7 | d9 e8 94 32 40 47 f8 45 32 d3 14 ad 34 08 df 4c | e3 3c 47 87 66 1f 92 15 c8 da 17 ad 03 77 7a 7b | 15 9f 58 a2 1f 71 ef a1 41 9e 58 ac 50 98 c6 43 | aa a2 be 0a bd 1e d6 87 aa cd 38 4e 81 99 f1 ab | 1b 31 27 cc 4b ea fb 09 4b 98 32 d2 | !event_already_set at reschedule | event_schedule: new EVENT_RETRANSMIT-pe@0x7f8638002b78 | inserting event EVENT_RETRANSMIT, timeout in 0.5 seconds for #4 | libevent_malloc: new ptr-libevent@0x7f8630002888 size 128 | #4 STATE_QUICK_R1: retransmits: first event in 0.5 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11182.409641 | pstats #4 ikev1.ipsec established | NAT-T: encaps is 'auto' "TUNNEL-C" #4: STATE_QUICK_R1: sent QR1, inbound IPsec SA installed, expecting QI2 tunnel mode {ESP=>0x2605d62c <0x58b85bc4 xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #4 suppresed complete_v1_state_transition() | #4 spent 1.82 milliseconds in resume sending helper answer | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f86440027d8 | spent 0.00391 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 76 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 af 95 83 06 00 00 00 4c 17 7f 41 57 | ad 57 85 50 32 cf 98 76 38 37 ce 22 f3 9f c4 17 | f9 4e 38 37 25 2f 8b a1 e8 91 d5 57 9e 9c 21 8b | fc 76 d1 43 bf e8 a5 c4 1f 7c 76 71 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 2945811206 (0xaf958306) | length: 76 (0x4c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: found IKEv1 state #4 in QUICK_R1 (find_state_ikev1) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1633) | #4 is idle | #4 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x100 opt: 0x0 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | removing 12 bytes of padding | quick_inI2 HASH(3): | a8 f4 9b 50 32 59 7e b3 4c ce 5b 42 b8 03 20 34 | ac c7 b7 e9 8e ef 5a 74 b2 24 78 7e d7 71 8a ae | received 'quick_inI2' message HASH(3) data ok | install_ipsec_sa() for #4: outbound only | could_route called for TUNNEL-C (kind=CK_PERMANENT) | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-C" unrouted: "TUNNEL-B" erouted; eroute owner: NULL | sr for #4: unrouted | route_and_eroute() for proto 0, and source port 0 dest port 0 | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-C" unrouted: "TUNNEL-B" erouted; eroute owner: NULL | route_and_eroute with c: TUNNEL-C (next: none) ero:null esr:{(nil)} ro:TUNNEL-B rosr:{0x56546b818d28} and state: #4 | priority calculation of connection "TUNNEL-C" is 0xfdfdf | eroute_connection add eroute 192.0.2.234/32:0 --0-> 192.0.1.254/32:0 => tun.0@192.1.2.45 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | running updown command "ipsec _updown" for verb up | command executing up-client | executing up-client: PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.234/32' PLUTO_MY_CLIENT_NET='192.0.2.234' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMIL | popen cmd is 1313 chars long | cmd( 0):PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_INT: | cmd( 80):ERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=C: | cmd( 160):A, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libre: | cmd( 240):swan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.234/32' PL: | cmd( 320):UTO_MY_CLIENT_NET='192.0.2.234' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_: | cmd( 400):PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLUTO_: | cmd( 480):PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Te: | cmd( 560):st Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org': | cmd( 640): PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PE: | cmd( 720):ER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLU: | cmd( 800):TO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+E: | cmd( 880):NCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND: | cmd( 960):='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_MY_SOURCEIP='1: | cmd(1040):92.0.2.234' PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INF: | cmd(1120):O='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CON: | cmd(1200):FIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x2605d62c SPI_: | cmd(1280):OUT=0x58b85bc4 ipsec _updown 2>&1: | route_and_eroute: firewall_notified: true | route_and_eroute: instance "TUNNEL-C", setting eroute_owner {spd=0x56546b819318,sr=0x56546b819318} to #4 (was #0) (newest_ipsec_sa=#0) | #1 spent 0.947 milliseconds in install_ipsec_sa() | inI2: instance TUNNEL-C[0], setting IKEv1 newest_ipsec_sa to #4 (was #0) (spd.eroute=#4) cloned from #1 | DPD: dpd_init() called on IPsec SA | DPD: Peer does not support Dead Peer Detection | complete v1 state transition with STF_OK | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #4 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_R1 to state STATE_QUICK_R2 | child state #4: QUICK_R1(established CHILD SA) => QUICK_R2(established CHILD SA) | event_already_set, deleting event | state #4 requesting EVENT_RETRANSMIT to be deleted | #4 STATE_QUICK_R2: retransmits: cleared | libevent_free: release ptr-libevent@0x7f8630002888 | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f8638002b78 | !event_already_set at reschedule | event_schedule: new EVENT_SA_REPLACE-pe@0x7f8638002b78 | inserting event EVENT_SA_REPLACE, timeout in 28799 seconds for #4 | libevent_malloc: new ptr-libevent@0x7f86440027d8 size 128 | pstats #4 ikev1.ipsec established | NAT-T: encaps is 'auto' "TUNNEL-C" #4: STATE_QUICK_R2: IPsec SA established tunnel mode {ESP=>0x2605d62c <0x58b85bc4 xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | #4 spent 1.06 milliseconds in process_packet_tail() | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 1.27 milliseconds in comm_handle_cb() reading and processing packet | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00517 milliseconds in signal handler PLUTO_SIGCHLD | processing global timer EVENT_SHUNT_SCAN | expiring aged bare shunts from shunt table | spent 0.00307 milliseconds in global timer EVENT_SHUNT_SCAN | processing global timer EVENT_NAT_T_KEEPALIVE | FOR_EACH_STATE_... in nat_traversal_ka_event (for_each_state) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-C | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.45:500 (state=#4) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #4) | ff | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-B | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.45:500 (state=#3) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #3) | ff | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-A | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.45:500 (state=#2) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #2) | ff | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-C | stop processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in for_each_state() at state.c:1577) | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | spent 0.464 milliseconds in global timer EVENT_NAT_T_KEEPALIVE | spent 0.0034 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.45:500 | spent 0.0118 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00167 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.45:500 | spent 0.00657 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00161 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.45:500 | spent 0.00607 milliseconds in comm_handle_cb() reading and processing packet | processing global timer EVENT_SHUNT_SCAN | expiring aged bare shunts from shunt table | spent 0.00318 milliseconds in global timer EVENT_SHUNT_SCAN | processing global timer EVENT_NAT_T_KEEPALIVE | FOR_EACH_STATE_... in nat_traversal_ka_event (for_each_state) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-C | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.45:500 (state=#4) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #4) | ff | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-B | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.45:500 (state=#3) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #3) | ff | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-A | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.45:500 (state=#2) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #2) | ff | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-C | stop processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in for_each_state() at state.c:1577) | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | spent 0.403 milliseconds in global timer EVENT_NAT_T_KEEPALIVE | spent 0.00263 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.45:500 | spent 0.0103 milliseconds in comm_handle_cb() reading and processing packet | spent 0.0013 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.45:500 | spent 0.0058 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00117 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.45:500 | spent 0.0051 milliseconds in comm_handle_cb() reading and processing packet | processing global timer EVENT_PENDING_DDNS | FOR_EACH_CONNECTION_... in connection_check_ddns | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | elapsed time in connection_check_ddns for hostname lookup 0.000005 | spent 0.00825 milliseconds in global timer EVENT_PENDING_DDNS | processing global timer EVENT_SHUNT_SCAN | expiring aged bare shunts from shunt table | spent 0.0022 milliseconds in global timer EVENT_SHUNT_SCAN | timer_event_cb: processing event@0x56546b81a948 | handling event EVENT_SA_REPLACE for parent state #1 | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in timer_event_cb() at timer.c:250) | picked newest_isakmp_sa #1 for #1 | replacing stale ISAKMP SA | dup_any(fd@-1) -> fd@-1 (in ipsecdoi_replace() at ipsec_doi.c:310) | creating state object #5 at 0x56546b83cd18 | State DB: adding IKEv1 state #5 in UNDEFINED | pstats #5 ikev1.isakmp started | suspend processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in main_outI1() at ikev1_main.c:118) | start processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in main_outI1() at ikev1_main.c:118) | parent state #5: UNDEFINED(ignore) => MAIN_I1(half-open IKE SA) "TUNNEL-C" #5: initiating Main Mode to replace #1 | **emit ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | 00 00 00 00 00 00 00 00 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 1:ISAKMP_NEXT_SA | no specific IKE algorithms specified - using defaults | oakley_alg_makedb() processing ealg=aes=7 halg=sha2_256=4 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=aes=7 halg=sha2_512=6 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=aes=7 halg=sha=2 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=aes=7 halg=sha2_256=4 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() processing ealg=aes=7 halg=sha2_512=6 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() processing ealg=aes=7 halg=sha=2 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha2_256=4 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha2_512=6 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha=2 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha2_256=4 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha2_512=6 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha=2 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() returning 0x56546b842288 | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ikev1_out_sa pcn: 0 has 1 valid proposals | ikev1_out_sa pcn: 0 pn: 0<1 valid_count: 1 trans_cnt: 18 | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 18 (0x12) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 1 (0x1) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 2 (0x2) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 3 (0x3) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 4 (0x4) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 5 (0x5) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 6 (0x6) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 7 (0x7) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 8 (0x8) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 9 (0x9) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 10 (0xa) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 11 (0xb) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 12 (0xc) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 13 (0xd) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 14 (0xe) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 15 (0xf) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 16 (0x10) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP transform number: 17 (0x11) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | emitting length of ISAKMP Proposal Payload: 632 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 644 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | out_vid(): sending [FRAGMENTATION] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 40 48 b7 d5 6e bc e8 85 25 e7 de 7f 00 d6 c2 d3 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [Dead Peer Detection] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID af ca d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 | emitting length of ISAKMP Vendor ID Payload: 20 | nat add vid | sending draft and RFC NATT VIDs | out_vid(): sending [RFC 3947] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | emitting length of ISAKMP Vendor ID Payload: 20 | skipping VID_NATT_RFC | out_vid(): sending [draft-ietf-ipsec-nat-t-ike-03] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d 56 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [draft-ietf-ipsec-nat-t-ike-02_n] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 90 cb 80 91 3e bb 69 6e 08 63 81 b5 ec 42 7b 1f | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [draft-ietf-ipsec-nat-t-ike-02] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID cd 60 46 43 35 df 21 f8 7c fd b2 fc 68 b6 a4 48 | emitting length of ISAKMP Vendor ID Payload: 20 | no IKEv1 message padding required | emitting length of ISAKMP Message: 792 | sending 792 bytes for reply packet for main_outI1 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #5) | 7a 3e ee d8 64 fe 14 54 00 00 00 00 00 00 00 00 | 01 10 02 00 00 00 00 00 00 00 03 18 0d 00 02 84 | 00 00 00 01 00 00 00 01 00 00 02 78 00 01 00 12 | 03 00 00 24 00 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 01 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 04 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 02 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 06 | 80 03 00 03 80 04 00 0e 80 0e 01 00 03 00 00 24 | 03 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 06 80 03 00 03 80 04 00 0e 80 0e 00 80 | 03 00 00 24 04 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 02 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 05 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 02 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 06 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 04 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 07 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 04 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 24 08 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 06 80 03 00 03 80 04 00 05 | 80 0e 01 00 03 00 00 24 09 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 06 80 03 00 03 | 80 04 00 05 80 0e 00 80 03 00 00 24 0a 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 02 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 0b 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 02 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 20 0c 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 0e | 03 00 00 20 0d 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 0e | 03 00 00 20 0e 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 0e | 03 00 00 20 0f 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 05 | 03 00 00 20 10 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 05 | 00 00 00 20 11 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 05 | 0d 00 00 14 40 48 b7 d5 6e bc e8 85 25 e7 de 7f | 00 d6 c2 d3 0d 00 00 14 af ca d7 13 68 a1 f1 c9 | 6b 86 96 fc 77 57 01 00 0d 00 00 14 4a 13 1c 81 | 07 03 58 45 5c 57 28 f2 0e 95 45 2f 0d 00 00 14 | 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d 56 | 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 81 b5 | ec 42 7b 1f 00 00 00 14 cd 60 46 43 35 df 21 f8 | 7c fd b2 fc 68 b6 a4 48 | event_schedule: new EVENT_RETRANSMIT-pe@0x7f8630002b78 | inserting event EVENT_RETRANSMIT, timeout in 0.5 seconds for #5 | libevent_malloc: new ptr-libevent@0x7f8640003f28 size 128 | #5 STATE_MAIN_I1: retransmits: first event in 0.5 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11241.16756 | #5 spent 1.76 milliseconds in main_outI1() | stop processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in main_outI1() at ikev1_main.c:228) | event_schedule: new EVENT_SA_EXPIRE-pe@0x56546b7ba938 | inserting event EVENT_SA_EXPIRE, timeout in 1 seconds for #1 | libevent_malloc: new ptr-libevent@0x56546b813de8 size 128 | libevent_free: release ptr-libevent@0x56546b8380d8 | free_event_entry: release EVENT_SA_REPLACE-pe@0x56546b81a948 | #1 spent 1.81 milliseconds in timer_event_cb() EVENT_SA_REPLACE | processing: STOP state #0 (in timer_event_cb() at timer.c:557) | spent 0.00264 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 144 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 01 10 02 00 00 00 00 00 00 00 00 90 0d 00 00 38 | 00 00 00 01 00 00 00 01 00 00 00 2c 00 01 00 01 | 00 00 00 24 00 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 0d 00 00 14 40 48 b7 d5 6e bc e8 85 | 25 e7 de 7f 00 d6 c2 d3 0d 00 00 14 af ca d7 13 | 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 00 00 00 14 | 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 144 (0x90) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: IKEv1 state not found (find_state_ikev1) | State DB: found IKEv1 state #5 in MAIN_I1 (find_state_ikev1_init) | start processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in process_v1_packet() at ikev1.c:1459) | #5 is idle | #5 idle | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x2 opt: 0x2080 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 56 (0x38) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 20 (0x14) | message 'main_inR1_outI2' HASH payload not checked early | received Vendor ID payload [FRAGMENTATION] | received Vendor ID payload [Dead Peer Detection] | quirks.qnat_traversal_vid set to=117 [RFC 3947] | received Vendor ID payload [RFC 3947] | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | *****parse ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | OAKLEY proposal verified unconditionally; no alg_info to check against | Oakley Transform 0 accepted | sender checking NAT-T: enabled; VID 117 | returning NAT-T method NAT_TRAVERSAL_METHOD_IETF_RFC | enabling possible NAT-traversal with method RFC 3947 (NAT-Traversal) | adding outI2 KE work-order 9 for state #5 | state #5 requesting EVENT_RETRANSMIT to be deleted | #5 STATE_MAIN_I1: retransmits: cleared | libevent_free: release ptr-libevent@0x7f8640003f28 | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f8630002b78 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f8630002b78 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #5 | libevent_malloc: new ptr-libevent@0x7f8640003f28 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #5 and saving MD | #5 is busy; has a suspended MD | #5 spent 0.162 milliseconds in process_packet_tail() | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | crypto helper 1 resuming | stop processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in process_md() at demux.c:382) | crypto helper 1 starting work-order 9 for state #5 | processing: STOP connection NULL (in process_md() at demux.c:383) | crypto helper 1 doing build KE and nonce (outI2 KE); request ID 9 | spent 0.356 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 1 finished build KE and nonce (outI2 KE); request ID 9 time elapsed 0.000589 seconds | (#5) spent 0.592 milliseconds in crypto helper computing work-order 9: outI2 KE (pcr) | crypto helper 1 sending results from work-order 9 for state #5 to event queue | scheduling resume sending helper answer for #5 | libevent_malloc: new ptr-libevent@0x7f863c004fd8 size 128 | crypto helper 1 waiting (nothing to do) | processing resume sending helper answer for #5 | start processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in resume_handler() at server.c:797) | crypto helper 1 replies to request ID 9 | calling continuation function 0x56546aa07b50 | main_inR1_outI2_continue for #5: calculated ke+nonce, sending I2 | **emit ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value 72 00 a6 90 bb 47 cf e3 82 52 93 43 d3 93 44 76 | keyex value 37 19 13 c7 95 fd 00 29 5f a9 11 8a 7c 73 ad d7 | keyex value dc a7 5a 8e 3e d1 cd ef f3 56 e3 9f cd 76 5f 0a | keyex value 34 31 a4 3d 3c 63 16 19 1a a9 28 8e d2 9a ef 7a | keyex value 18 01 ec 8d 65 34 a7 8e 5e 35 50 91 98 b4 2f 03 | keyex value 67 a4 9a 4e b8 10 5e 58 5c f6 46 7f 26 eb 44 c8 | keyex value f2 7c 19 be 0e 46 e8 40 2f 3f 7d 05 b3 5f 29 c7 | keyex value ec 6a c6 56 29 7c 6b af 35 55 41 79 d1 82 ba cb | keyex value 17 57 cb 6e a9 b0 a2 89 b9 9e 22 a3 af b9 d0 ad | keyex value 12 be 27 01 94 da f6 be 70 36 30 59 f6 73 d4 83 | keyex value 94 1b 30 0c be 9c cf 7d 58 4c 09 9e 2c 34 1d 61 | keyex value e9 d7 9c 24 ee 8a 41 69 d4 13 f4 4c 08 fd da 70 | keyex value 60 a3 3e c9 6a 42 8b fa df 5c 30 7d dc f0 94 0f | keyex value 60 0f b7 a7 cb 11 5b 19 95 ef ca 2d 18 38 73 01 | keyex value 1c b0 29 58 80 d8 fc 4c 1e 71 76 9b 82 6c b2 31 | keyex value da dd c7 70 7c d7 02 1a 2a 50 70 58 0b 7c ba 13 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Ni into ISAKMP Nonce Payload | Ni fd 29 12 2e ca 58 1d 2b d6 ce af 60 38 ee c6 4a | Ni fd da 0f b7 bb a3 78 06 b0 60 24 94 7c 8c 30 e7 | emitting length of ISAKMP Nonce Payload: 36 | NAT-T checking st_nat_traversal | NAT-T found (implies NAT_T_WITH_NATD) | sending NAT-D payloads | natd_hash: hasher=0x56546aadcca0(32) | natd_hash: icookie= 7a 3e ee d8 64 fe 14 54 | natd_hash: rcookie= d3 7b 19 72 3b a4 45 7b | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= f0 c8 e4 b4 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 | natd_hash: hash= e8 f5 8d 02 e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | next payload chain: ignoring supplied 'ISAKMP NAT-D Payload'.'next payload type' value 20:ISAKMP_NEXT_NATD_RFC | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D f0 c8 e4 b4 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 | NAT-D e8 f5 8d 02 e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | emitting length of ISAKMP NAT-D Payload: 36 | natd_hash: hasher=0x56546aadcca0(32) | natd_hash: icookie= 7a 3e ee d8 64 fe 14 54 | natd_hash: rcookie= d3 7b 19 72 3b a4 45 7b | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= f9 1f 2a 23 a1 68 7b e1 bd 80 68 ae cd bf 8f 98 | natd_hash: hash= ac ef f5 82 c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP NAT-D Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D f9 1f 2a 23 a1 68 7b e1 bd 80 68 ae cd bf 8f 98 | NAT-D ac ef f5 82 c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | emitting length of ISAKMP NAT-D Payload: 36 | no IKEv1 message padding required | emitting length of ISAKMP Message: 396 | State DB: re-hashing IKEv1 state #5 IKE SPIi and SPI[ir] | complete v1 state transition with STF_OK | [RE]START processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in complete_v1_state_transition() at ikev1.c:2673) | #5 is idle | doing_xauth:no, t_xauth_client_done:no | peer supports fragmentation | peer supports DPD | IKEv1: transition from state STATE_MAIN_I1 to state STATE_MAIN_I2 | parent state #5: MAIN_I1(half-open IKE SA) => MAIN_I2(open IKE SA) | event_already_set, deleting event | state #5 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x7f8640003f28 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f8630002b78 | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 396 bytes for STATE_MAIN_I1 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #5) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | 72 00 a6 90 bb 47 cf e3 82 52 93 43 d3 93 44 76 | 37 19 13 c7 95 fd 00 29 5f a9 11 8a 7c 73 ad d7 | dc a7 5a 8e 3e d1 cd ef f3 56 e3 9f cd 76 5f 0a | 34 31 a4 3d 3c 63 16 19 1a a9 28 8e d2 9a ef 7a | 18 01 ec 8d 65 34 a7 8e 5e 35 50 91 98 b4 2f 03 | 67 a4 9a 4e b8 10 5e 58 5c f6 46 7f 26 eb 44 c8 | f2 7c 19 be 0e 46 e8 40 2f 3f 7d 05 b3 5f 29 c7 | ec 6a c6 56 29 7c 6b af 35 55 41 79 d1 82 ba cb | 17 57 cb 6e a9 b0 a2 89 b9 9e 22 a3 af b9 d0 ad | 12 be 27 01 94 da f6 be 70 36 30 59 f6 73 d4 83 | 94 1b 30 0c be 9c cf 7d 58 4c 09 9e 2c 34 1d 61 | e9 d7 9c 24 ee 8a 41 69 d4 13 f4 4c 08 fd da 70 | 60 a3 3e c9 6a 42 8b fa df 5c 30 7d dc f0 94 0f | 60 0f b7 a7 cb 11 5b 19 95 ef ca 2d 18 38 73 01 | 1c b0 29 58 80 d8 fc 4c 1e 71 76 9b 82 6c b2 31 | da dd c7 70 7c d7 02 1a 2a 50 70 58 0b 7c ba 13 | 14 00 00 24 fd 29 12 2e ca 58 1d 2b d6 ce af 60 | 38 ee c6 4a fd da 0f b7 bb a3 78 06 b0 60 24 94 | 7c 8c 30 e7 14 00 00 24 f0 c8 e4 b4 19 d1 3c 20 | da 9d 32 e8 6d 48 38 93 e8 f5 8d 02 e5 0e 9b aa | 5c d0 71 65 a1 8b 17 83 00 00 00 24 f9 1f 2a 23 | a1 68 7b e1 bd 80 68 ae cd bf 8f 98 ac ef f5 82 | c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | !event_already_set at reschedule | event_schedule: new EVENT_RETRANSMIT-pe@0x7f8630002b78 | inserting event EVENT_RETRANSMIT, timeout in 0.5 seconds for #5 | libevent_malloc: new ptr-libevent@0x56546b824d58 size 128 | #5 STATE_MAIN_I2: retransmits: first event in 0.5 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11241.169486 "TUNNEL-C" #5: STATE_MAIN_I2: sent MI2, expecting MR2 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #5 suppresed complete_v1_state_transition() | #5 spent 0.317 milliseconds in resume sending helper answer | stop processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f863c004fd8 | spent 0.00218 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 396 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | a1 44 47 96 63 aa 6d b2 d9 3b b6 c3 df 4f 20 eb | cb 86 40 67 d5 b7 94 ab 41 61 f4 e3 ba d5 c3 52 | 6d 85 e0 dc bf cb 07 33 99 c6 db f6 64 d8 75 36 | ad 1b 33 f5 53 11 9f c9 1e 30 92 18 97 c5 fe d2 | f7 77 e7 6f 6b 11 96 48 29 20 d3 d7 ed d1 0a 03 | f3 2a 41 b3 fa d5 65 c3 bd 1a bd 19 3e 25 5a 53 | 84 ab eb 40 9c cd 00 ed 47 f1 e3 46 d8 f1 73 f9 | 90 a2 f7 10 f1 ee e2 bd 15 f5 58 1a 7b 8a 45 90 | 7a c8 36 fe 2c a5 0b 5f db 02 4e 29 6b 99 a0 42 | e9 a7 c6 14 4f 68 6f fa 48 d8 1f f2 f0 9f d5 28 | 3b 08 25 2e 0a 6d 82 d1 85 de f2 ed 36 a4 5b 3e | d7 c7 c1 ad 55 55 b9 ff c5 8a 32 1f 55 e9 33 5a | 1d 68 04 3d 93 fd 79 fe f0 99 63 fe ec bb 26 a1 | 04 c4 7a e0 66 bb ce a9 e0 7e 17 89 4d d6 72 20 | 3c d9 a2 c7 ab 48 cb 82 47 c9 04 2a 13 8b 01 da | 11 9c 26 ab f5 09 96 3c 5f 95 14 8a 68 9b 27 2b | 14 00 00 24 1e d8 ac 0c 47 18 82 5e c4 b0 b1 43 | b8 51 90 14 2e d0 e2 11 45 4e 26 b2 14 a1 99 83 | 34 b4 6a 9a 14 00 00 24 f9 1f 2a 23 a1 68 7b e1 | bd 80 68 ae cd bf 8f 98 ac ef f5 82 c6 80 31 e3 | d8 0a ec eb 67 7a 29 39 00 00 00 24 f0 c8 e4 b4 | 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 e8 f5 8d 02 | e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_KE (0x4) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 396 (0x18c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #5 in MAIN_I2 (find_state_ikev1) | start processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in process_v1_packet() at ikev1.c:1459) | #5 is idle | #5 idle | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x410 opt: 0x102080 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 260 (0x104) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x102080 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | message 'main_inR2_outI3' HASH payload not checked early | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding aggr outR1 DH work-order 10 for state #5 | state #5 requesting EVENT_RETRANSMIT to be deleted | #5 STATE_MAIN_I2: retransmits: cleared | libevent_free: release ptr-libevent@0x56546b824d58 | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f8630002b78 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f8630002b78 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #5 | libevent_malloc: new ptr-libevent@0x7f863c004fd8 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #5 and saving MD | #5 is busy; has a suspended MD | crypto helper 3 resuming | crypto helper 3 starting work-order 10 for state #5 | #5 spent 0.0688 milliseconds in process_packet_tail() | crypto helper 3 doing compute dh+iv (V1 Phase 1) (aggr outR1 DH); request ID 10 | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.226 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 3 finished compute dh+iv (V1 Phase 1) (aggr outR1 DH); request ID 10 time elapsed 0.001115 seconds | (#5) spent 1.12 milliseconds in crypto helper computing work-order 10: aggr outR1 DH (pcr) | crypto helper 3 sending results from work-order 10 for state #5 to event queue | scheduling resume sending helper answer for #5 | libevent_malloc: new ptr-libevent@0x7f864000bcf8 size 128 | crypto helper 3 waiting (nothing to do) | processing resume sending helper answer for #5 | start processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in resume_handler() at server.c:797) | crypto helper 3 replies to request ID 10 | calling continuation function 0x56546aa07b50 | main_inR2_outI3_cryptotail for #5: calculated DH, sending R1 | **emit ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_ID (0x5) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 5:ISAKMP_NEXT_ID | thinking about whether to send my certificate: | I have RSA key: OAKLEY_RSA_SIG cert.type: CERT_X509_SIGNATURE | sendcert: CERT_ALWAYSSEND and I did not get a certificate request | so send cert. | I am sending a certificate request | I will NOT send an initial contact payload | init checking NAT-T: enabled; RFC 3947 (NAT-Traversal) | natd_hash: hasher=0x56546aadcca0(32) | natd_hash: icookie= 7a 3e ee d8 64 fe 14 54 | natd_hash: rcookie= d3 7b 19 72 3b a4 45 7b | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= f9 1f 2a 23 a1 68 7b e1 bd 80 68 ae cd bf 8f 98 | natd_hash: hash= ac ef f5 82 c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | natd_hash: hasher=0x56546aadcca0(32) | natd_hash: icookie= 7a 3e ee d8 64 fe 14 54 | natd_hash: rcookie= d3 7b 19 72 3b a4 45 7b | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= f0 c8 e4 b4 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 | natd_hash: hash= e8 f5 8d 02 e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | expected NAT-D(me): f9 1f 2a 23 a1 68 7b e1 bd 80 68 ae cd bf 8f 98 | expected NAT-D(me): ac ef f5 82 c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | expected NAT-D(him): | f0 c8 e4 b4 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 | e8 f5 8d 02 e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | received NAT-D: f9 1f 2a 23 a1 68 7b e1 bd 80 68 ae cd bf 8f 98 | received NAT-D: ac ef f5 82 c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | received NAT-D: f0 c8 e4 b4 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 | received NAT-D: e8 f5 8d 02 e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | NAT_TRAVERSAL encaps using auto-detect | NAT_TRAVERSAL this end is NOT behind NAT | NAT_TRAVERSAL that end is NOT behind NAT | NAT_TRAVERSAL nat-keepalive enabled 192.1.2.45 | NAT-Traversal: Result using RFC 3947 (NAT-Traversal) sender port 500: no NAT detected | NAT_T_WITH_KA detected | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_CERT (0x6) | ID type: ID_DER_ASN1_DN (0x9) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 6:ISAKMP_NEXT_CERT | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 183 raw bytes of my identity into ISAKMP Identification Payload (IPsec DOI) | my identity 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | my identity 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | my identity 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | my identity 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | my identity 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | my identity 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | my identity 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 61 73 | my identity 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | my identity 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | my identity 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | my identity 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | my identity 77 61 6e 2e 6f 72 67 | emitting length of ISAKMP Identification Payload (IPsec DOI): 191 "TUNNEL-C" #5: I am sending my cert | ***emit ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_CR (0x7) | cert encoding: CERT_X509_SIGNATURE (0x4) | next payload chain: ignoring supplied 'ISAKMP Certificate Payload'.'next payload type' value 7:ISAKMP_NEXT_CR | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Certificate Payload (6:ISAKMP_NEXT_CERT) | next payload chain: saving location 'ISAKMP Certificate Payload'.'next payload type' in 'reply packet' | emitting 1260 raw bytes of CERT into ISAKMP Certificate Payload | CERT 30 82 04 e8 30 82 04 51 a0 03 02 01 02 02 01 03 | CERT 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 | CERT 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 31 | CERT 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 69 | CERT 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 6f | CERT 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c 69 | CERT 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 0b | CERT 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 6e | CERT 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 72 | CERT 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 6f | CERT 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a 86 | CERT 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e 67 | CERT 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 30 22 | CERT 18 0f 32 30 31 39 30 38 32 34 30 39 30 37 35 33 | CERT 5a 18 0f 32 30 32 32 30 38 32 33 30 39 30 37 35 | CERT 33 5a 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 | CERT 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 | CERT 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 | CERT 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c | CERT 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 | CERT 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 | CERT 6d 65 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 | CERT 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a | CERT 86 48 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 | CERT 61 73 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 30 82 01 a2 30 0d 06 | CERT 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 8f | CERT 00 30 82 01 8a 02 82 01 81 00 b1 1e 7c b3 bf 11 | CERT 96 94 23 ca 97 5e c7 66 36 55 71 49 95 8d 0c 2a | CERT 5c 30 4d 58 29 a3 7b 4d 3b 3f 03 06 46 a6 04 63 | CERT 71 0d e1 59 4f 9c ec 3a 17 24 8d 91 6a a8 e2 da | CERT 57 41 de f4 ff 65 bf f6 11 34 d3 7d 5a 7f 6e 3a | CERT 3b 74 3c 51 2b e4 bf ce 6b b2 14 47 26 52 f5 57 | CERT 28 bc c5 fb f9 bc 2d 4e b9 f8 46 54 c7 95 41 a7 | CERT a4 b4 d3 b3 fe 55 4b df f5 c3 78 39 8b 4e 04 57 | CERT c0 1d 5b 17 3c 28 eb 40 9d 1d 7c b3 bb 0f f0 63 | CERT c7 c0 84 b0 4e e4 a9 7c c5 4b 08 43 a6 2d 00 22 | CERT fd 98 d4 03 d0 ad 97 85 d1 48 15 d3 e4 e5 2d 46 | CERT 7c ab 41 97 05 27 61 77 3d b6 b1 58 a0 5f e0 8d | CERT 26 84 9b 03 20 ce 5e 27 7f 7d 14 03 b6 9d 6b 9f | CERT fd 0c d4 c7 2d eb be ea 62 87 fa 99 e0 a6 1c 85 | CERT 4f 34 da 93 2e 5f db 03 10 58 a8 c4 99 17 2d b1 | CERT bc e5 7b bd af 0e 28 aa a5 74 ea 69 74 5e fa 2c | CERT c3 00 3c 2f 58 d0 20 cf e3 46 8d de aa f9 f7 30 | CERT 5c 16 05 04 89 4c 92 9b 8a 33 11 70 83 17 58 24 | CERT 2a 4b ab be b6 ec 84 9c 78 9c 11 04 2a 02 ce 27 | CERT 83 a1 1f 2b 38 3f 27 7d 46 94 63 ff 64 59 4e 6c | CERT 87 ca 3e e6 31 df 1e 7d 48 88 02 c7 9d fa 4a d7 | CERT f2 5b a5 fd 7f 1b c6 dc 1a bb a6 c4 f8 32 cd bf | CERT a7 0b 71 8b 2b 31 41 17 25 a4 18 52 7d 32 fc 0f | CERT 5f b8 bb ca e1 94 1a 42 4d 1f 37 16 67 84 ae b4 | CERT 32 42 9c 5a 91 71 62 b4 4b 07 02 03 01 00 01 a3 | CERT 82 01 06 30 82 01 02 30 09 06 03 55 1d 13 04 02 | CERT 30 00 30 47 06 03 55 1d 11 04 40 30 3e 82 1a 65 | CERT 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 81 1a 65 61 73 74 40 | CERT 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | CERT 6e 2e 6f 72 67 87 04 c0 01 02 17 30 0b 06 03 55 | CERT 1d 0f 04 04 03 02 07 80 30 1d 06 03 55 1d 25 04 | CERT 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b | CERT 06 01 05 05 07 03 02 30 41 06 08 2b 06 01 05 05 | CERT 07 01 01 04 35 30 33 30 31 06 08 2b 06 01 05 05 | CERT 07 30 01 86 25 68 74 74 70 3a 2f 2f 6e 69 63 2e | CERT 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | CERT 6e 2e 6f 72 67 3a 32 35 36 30 30 3d 06 03 55 1d | CERT 1f 04 36 30 34 30 32 a0 30 a0 2e 86 2c 68 74 74 | CERT 70 3a 2f 2f 6e 69 63 2e 74 65 73 74 69 6e 67 2e | CERT 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 2f 72 65 | CERT 76 6f 6b 65 64 2e 63 72 6c 30 0d 06 09 2a 86 48 | CERT 86 f7 0d 01 01 0b 05 00 03 81 81 00 3a 56 a3 7d | CERT b1 4e 62 2f 82 0d e3 fe 74 40 ef cb eb 93 ea ad | CERT e4 74 8b 80 6f ae 8b 65 87 12 a6 24 0d 21 9c 5f | CERT 70 5c 6f d9 66 8d 98 8b ea 59 f8 96 52 6a 6c 86 | CERT d6 7d ba 37 a9 8c 33 8c 77 18 23 0b 1b 2a 66 47 | CERT e7 95 94 e6 75 84 30 d4 db b8 23 eb 89 82 a9 fd | CERT ed 46 8b ce 46 7f f9 19 8f 49 da 29 2e 1e 97 cd | CERT 12 42 86 c7 57 fc 4f 0a 19 26 8a a1 0d 26 81 4d | CERT 53 f4 5c 92 a1 03 03 8d 6c 51 33 cc | emitting length of ISAKMP Certificate Payload: 1265 "TUNNEL-C" #5: I am sending a certificate request | ***emit ISAKMP Certificate RequestPayload: | next payload type: ISAKMP_NEXT_SIG (0x9) | cert type: CERT_X509_SIGNATURE (0x4) | next payload chain: ignoring supplied 'ISAKMP Certificate RequestPayload'.'next payload type' value 9:ISAKMP_NEXT_SIG | next payload chain: setting previous 'ISAKMP Certificate Payload'.'next payload type' to current ISAKMP Certificate RequestPayload (7:ISAKMP_NEXT_CR) | next payload chain: saving location 'ISAKMP Certificate RequestPayload'.'next payload type' in 'reply packet' | emitting length of ISAKMP Certificate RequestPayload: 5 | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAbEef vs PKK_RSA:AwEAAbEef | ***emit ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Certificate RequestPayload'.'next payload type' to current ISAKMP Signature Payload (9:ISAKMP_NEXT_SIG) | next payload chain: saving location 'ISAKMP Signature Payload'.'next payload type' in 'reply packet' | emitting 384 raw bytes of SIG_I into ISAKMP Signature Payload | SIG_I ad 67 6b fe 59 af ec 0e 77 aa 90 3c d4 fd 80 24 | SIG_I 83 81 ca 71 c4 54 c4 34 82 25 e4 6e 84 3d 10 d2 | SIG_I 52 b8 dd 89 c6 ef 3b d4 00 ba fe ee a4 c9 aa cb | SIG_I 25 91 bb 4e 0f b0 ff d9 19 76 db 42 1d 3e 7f 96 | SIG_I ff db 98 74 8d 34 71 9e 34 1f 4f b7 aa 03 61 af | SIG_I 8c 2f 18 99 86 54 ba d3 9d fc 8b 98 b2 42 fc 74 | SIG_I 33 b3 e7 f4 b0 6c ec 1e a4 eb c2 9e 91 e6 f0 78 | SIG_I 74 f8 62 bb e1 81 b7 12 97 d1 4b c1 9b 91 ae 21 | SIG_I 58 dc 66 55 7d bb a8 40 9c 5c 7a d8 bf 63 5c 3f | SIG_I c3 90 03 2f ae 37 07 62 2c bc ac 53 6d 52 1c d1 | SIG_I a7 96 47 98 c6 5a cd 9a 0e 8e 5a 75 70 44 57 74 | SIG_I 30 44 54 bd f4 47 c9 11 ab 94 3f 67 d0 2d 79 f9 | SIG_I a5 e6 24 bd 6d ce 84 60 c6 2f 05 79 99 1d 2e a4 | SIG_I e4 7c d8 b4 1b 31 61 aa 7c ce 27 fa 82 01 cb 40 | SIG_I 7a e3 97 bb 13 54 74 3c f6 b8 c1 99 c1 77 62 cf | SIG_I 4e 84 20 58 88 03 a1 d6 c9 9d ce 37 b3 0e 0a 42 | SIG_I 56 dc f9 e3 cc b5 ed c7 7b ba 2e 2d 82 52 b9 4a | SIG_I ad bb 95 64 e7 c7 ec 9f 52 af cc f5 e9 05 d4 bc | SIG_I fb 55 c7 d2 9f 7b 2f 2f 9d a5 00 28 ee 34 2f cf | SIG_I 5c 97 39 d0 24 f4 7b 74 06 b7 9c f6 90 fc b9 6c | SIG_I 29 1d 21 36 9c 91 f1 3e cf 22 22 a3 54 a6 70 00 | SIG_I f7 a3 94 c1 c9 99 13 77 7a 14 85 94 cc 66 4a a4 | SIG_I 76 d6 d3 ce 09 da 3b df 5c 5d 9e 05 53 83 bc bd | SIG_I 2f 26 da 67 a4 ef 13 cf 46 95 18 f2 0e f9 27 50 | emitting length of ISAKMP Signature Payload: 388 | Not sending INITIAL_CONTACT | emitting 7 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 1884 | complete v1 state transition with STF_OK | [RE]START processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in complete_v1_state_transition() at ikev1.c:2673) | #5 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_MAIN_I2 to state STATE_MAIN_I3 | parent state #5: MAIN_I2(open IKE SA) => MAIN_I3(open IKE SA) | event_already_set, deleting event | state #5 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x7f863c004fd8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f8630002b78 | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 1884 bytes for STATE_MAIN_I2 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #5) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 05 10 02 01 00 00 00 00 00 00 07 5c 9e aa 71 29 | ad 1e e5 00 d4 ad 93 93 8a 03 70 24 fb c4 a7 18 | f6 98 c5 9e aa 43 9f 23 bf cd d6 8d 6c 20 c9 ec | be e2 1b 33 e4 e5 ec 19 b6 31 9e 24 f2 e7 bd f4 | ec 3e 82 d6 42 b2 c8 2f 9e 2b 7b 2b c6 c3 75 e1 | b7 3d 24 a8 22 e0 a2 e3 ad 19 30 57 c9 13 74 08 | 11 26 8f f6 06 92 7d dd 31 62 2a 0e 71 09 92 34 | 3a f6 79 9d d2 53 c7 24 73 51 0a 6e 5d 62 64 e9 | 50 13 bc 9c 78 62 35 63 a6 52 17 1d 91 1e b2 c4 | 90 6a 47 6d 21 ab 04 46 bd 4b 02 11 ad aa 7e d7 | 76 84 fc 5d f6 c3 2c 74 4a c6 06 0b db 02 c8 de | a7 f8 84 bf e4 bb 1b 56 5b f5 58 8b e9 60 ec 09 | b5 8a f0 53 fe 5e 8a aa 07 fd 82 ea 10 20 23 41 | b5 ef 1b a2 25 aa 83 85 50 1c e8 7a 18 1a 64 7c | 85 a4 88 45 75 33 ed ec db 4b fe 6e f9 f1 e8 ea | fb 8b 78 f3 a8 de 08 e2 24 97 fa 1c 9e c4 c9 65 | e0 96 5a 13 67 1c 12 ed 82 89 59 e6 9c 55 49 f3 | a1 12 c4 fe 1d db 9a fd db cb 01 65 e7 6e c1 65 | 4b 49 95 95 8a 63 66 a7 ca 10 a7 9c 0c d9 74 22 | 97 4d cb 5d df 1e 02 06 b1 ed 0e b9 23 c9 1b c5 | d0 bf 11 5c 2f ac d0 c4 b8 4c 9f 65 e3 8f 49 10 | 64 4a 30 b2 5c 53 24 ac ce 90 50 a8 db 2f 8f 43 | 13 25 31 f1 a4 5d 7f 0f fa 2f 4b 52 88 0f 65 96 | 3a a4 d6 ce b1 60 48 42 30 54 c7 1e db 60 5b 6f | 70 3a f7 47 1c cc 9f 2a cd 7f df b7 98 b3 7c 11 | 04 da ab 87 3d 42 8b 9e cf 04 57 51 70 4b 1c 75 | 4c 08 0a b8 46 48 a2 f3 32 d0 45 75 8a 93 38 95 | 6d 4c e6 90 18 85 52 be 3c 26 d3 c4 78 13 28 1e | 91 8c 1f 59 2d 9f 79 00 43 41 93 75 4d 49 e9 a3 | 84 59 a0 8b 8c 49 55 76 93 65 84 2c 2e 76 c9 b5 | 7e 4b f0 74 73 47 12 63 a3 0f e8 87 ff 1c fd c4 | 84 d3 42 bb 24 b5 f3 5e 1e 42 6c c5 5e 04 c9 3d | 86 6e 5b 26 31 81 16 27 92 a7 18 63 a0 35 36 82 | 90 50 98 7e 75 54 da f2 ea e7 66 26 b9 53 36 2a | 75 46 55 86 1f 4d bf e6 cf d2 7b 44 c3 3b 0b 62 | 80 a2 12 3a 34 1d 65 ef 9a e6 7f 6a aa de 2f 57 | 3b c7 dc 41 e5 8a 97 f5 00 9b 9b dc 66 a8 1e 05 | 7a cc 17 20 fa a1 07 e8 c2 bd 0c 80 8d ee b5 dd | 6a 58 d9 6e e3 cd 8d 44 7f 1a 5f 51 f4 cb b7 49 | 16 39 d6 29 c0 57 f4 23 16 08 6d 15 6e b8 ca 97 | 76 da 03 14 bb 32 ba 82 03 bd bf a8 f5 37 3c 4a | 82 61 7e 3a 6e 8a bc 6c 56 18 17 ab dd a3 d0 3f | b3 31 80 7e 2f 70 42 69 8f 29 d0 c0 c6 d5 d4 3a | 8d 0c ad 58 72 16 cd 99 32 9d 2d c4 02 52 c4 2f | 2d 0a d7 f3 a7 71 50 d3 3d f2 41 b2 c5 22 fd bc | 93 7d f6 b8 b7 fc e1 ab 14 71 d2 c8 fa 15 fb 2e | ef 28 d5 a7 8a 8e b4 04 24 81 ac fa f5 36 90 df | 03 6b 61 49 25 2a e5 bb ad 67 d8 9f 76 88 f1 06 | 32 6a 86 79 fc d0 0f d8 8f 0f f9 48 fb f9 e3 f5 | 3e 65 7e f1 5d 2e 00 2f 8f 14 35 38 c3 6d 25 3f | 67 d2 d4 79 e4 ed 5c 3d 03 ab 6d d8 0a b5 38 2e | 4c 3f c3 0f 27 ee d3 20 98 21 7c b6 ff aa 18 42 | 6d 5f fc 0e b3 bb 87 40 c1 b6 bd 99 06 37 e4 88 | 1f ea 0f 03 60 c0 16 89 90 43 f1 90 1c cb 93 25 | 63 8b 7e 3c 59 76 8a 21 89 7b 3a 82 60 76 ed 0f | fe 2a 20 a3 19 3e 12 28 e6 02 85 d4 31 75 27 5d | 5a 46 c0 05 c9 93 69 12 79 22 86 a7 11 70 73 d4 | d6 34 18 45 78 30 f4 e0 f3 64 52 72 f1 6f a4 2c | a7 33 5b f6 1c 8c b9 96 1d 35 ec 04 cd fa 6e e1 | 92 1f c8 01 f6 6e bd c1 79 aa 82 ec fd 5e 50 68 | 20 2e 87 d7 c3 5f b9 a8 58 e1 77 7f 8c b6 c8 fc | 39 78 73 5c fd 53 c8 82 e5 56 d1 12 a5 7f d4 3f | 58 b0 0b c0 b2 f2 55 8e 29 36 cf fd fd ac 22 7e | fd 7e 04 2a 50 39 11 b8 cd b6 20 70 8f 1d c2 9f | 67 49 a3 6e 7f c7 f9 91 dc 49 e1 30 88 90 70 bc | c1 66 3d 70 15 a4 7c 5c 7b c9 b8 c6 b8 74 c7 40 | 06 cf 4d 8a c1 f5 b4 94 9f eb ef 28 f3 a7 38 b6 | 11 fb 86 81 2b 08 9a 6a 15 ec 76 13 3b d6 e7 03 | 9e bc 06 91 66 d3 bf 66 d3 01 db 4f 03 98 06 7b | 5e b4 58 d4 96 51 eb a0 36 2a 08 f2 5b 8f 88 49 | 54 66 53 7a 05 34 8b 6e 3b c2 24 d8 5d 7c a6 c2 | f6 e9 dc 42 1c 32 a8 15 64 15 07 d2 09 12 b4 3d | 1c 52 3f 31 93 de 89 29 40 5d 0c c8 74 64 04 7d | 42 ed 8b 19 e4 cc f4 d4 f1 45 20 32 f5 f8 1d 24 | 79 8c 5f c0 39 68 56 3d 15 e4 02 da d4 ad e1 c8 | 5c aa 4a 24 ca 13 c1 27 01 0a 54 b9 0b 9c 96 8c | d6 c3 92 4e 52 dd 4c af 9e 76 ad 42 68 4f 48 51 | c3 4d 92 d7 4a 5c 9b 92 23 5c cd 0a 71 18 88 07 | d3 c2 3f 13 bc 95 62 d6 21 9d f5 f6 30 60 3e 89 | e8 45 ed 13 3f 8a de 4f e4 0b a5 28 2e 14 e6 70 | 49 a3 48 a4 37 4c 60 e6 d8 4a 5e 53 c7 90 1b f3 | d3 9e e3 39 8d b2 63 16 6b 75 db 12 3e d3 01 9c | f1 12 e6 ab 93 a1 c8 22 15 1f 37 72 09 5a 94 3b | 05 4f 1c 37 39 03 ee 4e 43 a1 55 df 24 a5 1b ea | 79 82 1e 3e 19 07 e2 b1 d9 88 f4 04 71 3e 60 4f | 43 92 cf 6f 34 d5 9a 7c 54 72 49 55 d5 d9 af 0f | b5 cc 3d e0 d4 32 05 4c a9 c8 b6 10 64 a8 51 19 | d7 67 88 ca e7 f9 45 df d9 5d 8b 61 91 ba 46 91 | 7b 2d bd aa de 61 9c 7a b6 9c b6 6f a0 8f 0f 72 | 44 50 84 82 3c 9d 93 60 82 97 30 79 ed 58 3f e6 | 43 30 78 08 3e 40 44 4c fe cd e8 a3 c1 25 71 e4 | 92 eb 7a 51 a1 21 c0 ab 72 e0 24 04 eb b7 9c fd | 89 64 6d f2 94 7a 8b 5f 6d a9 94 00 f3 14 3a bf | 94 bc 27 c8 f9 7f 72 a9 4a 6e bd 17 90 38 da 9f | b5 0a 62 55 89 db a7 18 35 d4 15 65 2b 49 ae 97 | 5f b3 e9 fb 64 ef 2c e7 39 a5 c6 fc e1 bb 88 dd | 80 0f e4 8c 51 f2 31 5a a4 61 32 06 93 b9 d1 9e | 1e 02 31 54 1f d3 8e 63 2f ae c0 f0 ab f8 fb c7 | 93 76 5d 10 b9 4d 61 2e d9 58 fd b4 a8 66 25 f9 | e2 b6 59 f6 6f d2 92 52 7a 97 67 83 3f 43 0b 43 | 61 bb 4c ff 72 cf 21 78 90 b9 9b 3c b0 56 97 9a | 92 0f 37 e7 d9 7a 56 5e d3 1e 47 7a 48 45 17 a2 | 84 ed 09 14 8e cd 3f d7 52 2f b7 45 38 95 24 75 | 6b 9e 7b 05 c1 03 3c 72 0a f9 89 d1 aa 54 79 d5 | b8 93 b5 57 f7 7b 23 d6 08 af b9 50 9e f6 f3 66 | 22 2a 7e a6 53 62 01 84 fb 78 58 88 01 fb 49 46 | 1a cb 14 8f a0 41 d1 18 69 d9 9d be 62 59 79 70 | 22 ca 87 d3 87 30 3e c2 04 9e 23 22 88 24 ad 8f | f7 8b ec 6e ea 0d b7 4a 08 3a c9 35 bc 48 c7 3d | 7b 53 ca d0 84 08 28 7e b0 82 c9 4b c6 59 da fd | 26 b9 83 21 18 06 56 4e 12 8c e4 2d 82 c1 88 fb | 9b c9 49 b6 c6 b9 ea 92 57 13 86 9d a2 44 cb 0f | 65 43 0d 4c 18 f8 a9 85 f2 92 99 11 2d 72 6c 75 | 6f 92 16 9f 70 dc ac b7 64 da dd ba e6 92 ca 88 | 9f 4d 14 05 6d 15 78 12 46 e9 32 fe a5 9d 78 06 | 6b d6 4a f0 70 3c b6 04 59 15 e0 5a ae 4d da 52 | e0 dc 10 6c 0e c4 50 3b 67 7e 25 47 | !event_already_set at reschedule | event_schedule: new EVENT_RETRANSMIT-pe@0x7f8630002b78 | inserting event EVENT_RETRANSMIT, timeout in 0.5 seconds for #5 | libevent_malloc: new ptr-libevent@0x56546b81ed58 size 128 | #5 STATE_MAIN_I3: retransmits: first event in 0.5 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11241.178854 "TUNNEL-C" #5: STATE_MAIN_I3: sent MI3, expecting MR3 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #5 suppresed complete_v1_state_transition() | #5 spent 6.39 milliseconds in resume sending helper answer | stop processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f864000bcf8 | spent 0.00267 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 1884 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 05 10 02 01 00 00 00 00 00 00 07 5c 5f ae 07 51 | 17 78 00 ef c1 fe d5 b2 1c 9f 4f b7 97 07 fd 4d | d0 98 1f 4d cc 49 e7 01 d0 ff a8 36 a3 12 dc 50 | 30 04 2f 2b fd 05 ef 6a 5e 08 8d e4 15 c5 6e ed | d2 5c cb bb 7b 59 e4 1b 91 d1 24 32 b9 3b 95 c4 | 01 3a 57 c5 1e b6 f3 d2 0d 5b 1f 12 95 49 bd 4d | fa eb 7a cd 87 3b f8 91 03 1a 28 e5 71 70 5d bb | 04 23 93 de 52 36 2c e7 a7 84 bf d3 00 ef 78 c0 | 57 ac 9d 96 79 0e e3 1f a4 b1 38 a2 d3 af ca a5 | aa 90 c1 43 88 de 50 b7 4b 97 8c 3b bf e3 53 8d | f4 ba f1 d2 95 1a d0 5a ec 7c 6f 9f ba 7a b8 cd | e9 c0 da 5a b7 f0 6d 1f 11 04 13 0d 14 26 46 2b | 85 79 a0 cc 21 ab b2 49 96 d8 2e 87 0a 25 5e 77 | a0 c1 2a 0d c3 25 ea aa 18 94 37 13 6c 01 11 98 | 5c 7e 8e 39 aa b7 42 50 39 cc 81 88 a5 bd 76 fe | 8f a0 2d 40 0e 6f ac 25 c7 8d 7e 48 8d 65 8a 36 | 22 fb a7 b3 a4 e0 0f 5c d0 d5 d7 78 7b c5 87 74 | 15 78 14 72 ca ff cc 8b 2c ca c8 62 92 27 b7 7c | fd 31 89 83 81 fd 45 de ac 36 ce 0e cb 95 af c4 | 59 2e 36 c7 dd 6c 2c 51 f5 1d b0 e8 74 38 53 d7 | 7c 5f 05 a5 b4 2e 05 8e 3b 71 8d 01 f2 a7 e3 17 | e3 aa 64 b5 4d ad 4e 0e a0 85 6e 6f 56 08 03 ac | ce d7 4b 56 41 c8 13 c9 df 18 d6 a5 42 25 af 2b | 50 d6 7d 3a 7b 5a 66 ae 22 f3 1b 5f 55 27 d5 86 | 6d 80 58 02 4e d1 71 d4 af 40 46 ef 1a 1a 3e c4 | c5 7e 45 91 c9 dc 2a 9c c5 0e 54 8d 58 08 f9 34 | 50 0e c9 bc 8f e3 3d 3f 51 35 1e 16 e1 03 dc 1c | dd 87 70 1c 9e bd c5 d2 02 d2 fe 9f 5c 4a ff fd | 76 ae 6e 08 bc b5 65 23 32 8f de 6d 94 06 e2 09 | 2e c6 e3 a0 91 90 3c f7 b3 38 24 f6 02 60 14 b2 | bf 41 3b 6d ca 0d 2e 1f 2b d4 50 06 e0 d9 60 54 | e3 e3 83 d6 df 2c 64 67 d9 c8 ed 73 d5 59 24 5d | 09 4a 10 ab 9a 1b c1 30 ec 7c c5 a4 6e 09 7d 49 | 92 36 d3 67 1b 2e 4c bc 4d f7 9a 23 84 79 68 f3 | d5 9b da 9d 71 6c 48 c8 f6 00 e9 05 be bc da af | 9a a2 8b 78 0f c5 d9 70 1a 08 21 c0 e3 0c 4c f1 | d0 51 93 40 a3 99 26 aa a3 53 27 98 1a e9 0a 93 | 2a ad 67 4d 0c cf b6 99 f5 d3 03 88 dc 41 57 61 | 70 27 af d7 61 1b 65 f8 a4 fb 01 46 2f c4 8c f9 | 8e 6e 10 91 7c a3 c0 48 27 1c f5 d9 e6 e1 37 f8 | f1 a7 50 f2 9c fe 22 da 9f 82 b0 e3 69 35 49 bc | 2c 3f d3 ef e9 88 0f 28 8f ea 02 a9 53 a7 7c 86 | 0b be 92 8a 17 69 81 20 75 ce c0 0d c0 00 69 d8 | 65 6f e2 e1 5a 93 6e 89 e4 5e 76 70 f1 b9 a0 88 | bb e2 82 b3 e8 0e 5a 7c 64 36 b8 61 d9 08 24 3f | c3 98 40 0c b9 8e 11 65 99 2e 23 6f 39 80 24 a8 | 0e 65 4b 41 dd 28 f9 db d3 5e 28 00 7b 11 14 96 | aa f2 03 59 3c 9f ad 36 7b 6b a0 7a a6 5e f0 1a | 39 8b 78 12 e3 96 2a 25 03 65 74 73 26 24 d8 b4 | 63 3c 84 76 ed 44 91 e9 22 df 7c 45 5b 5d cb c3 | 64 fd 1b 4f 93 96 12 67 a7 18 f5 05 56 11 83 6f | b5 a8 22 5f 7a 27 20 0e 32 4f 92 91 40 4f 90 b0 | b9 ad 26 4b 29 99 a9 ea 6f 61 c5 4e 66 bd 4f f2 | a8 d9 20 c7 f9 8a 21 af 14 e2 7c 8a 32 19 e8 ea | 5a d6 53 b6 78 16 fa b4 c5 e2 60 b9 e4 34 d4 10 | 45 8a 0e 4e 7d 57 8c 15 c0 a9 b5 27 21 45 95 66 | fe c4 5e ee 1a ea 01 3d a2 3b a6 51 fa 74 e1 85 | 0e f3 1e 6c d2 74 e7 69 b9 18 b0 2c 23 03 8d 9e | 4d b8 07 a9 ff 16 85 be bb fc 7b 12 be 84 c6 e6 | 8d 60 6e 15 da 2b c6 ce 93 8b 2a 1b e6 8e 75 32 | e6 55 d5 62 da 26 55 6d 96 cf 9e 9e c4 59 56 e0 | fe 5f 94 d0 87 37 e0 c4 99 b1 17 ef ee de ae 07 | 41 1f a1 06 16 8e 1f 59 45 cf e0 f7 06 25 dd d1 | 75 a5 c2 54 0f 83 dd da 03 16 cf a4 07 a7 3a ac | 96 11 cb b8 38 4e 6b de d4 fe 68 0c 49 2a 16 58 | 62 01 be 23 29 db fb 7d 51 fc e9 7c 41 71 a4 96 | 41 c0 10 31 7d 0e f3 e7 3d 8d 2b 56 0a e5 00 0b | e2 e2 f7 58 3e db 18 d7 f6 32 6f b0 53 ef 14 d0 | a5 68 3f f5 9e a4 1c 62 db 03 d6 63 2f 18 2e d3 | ef 00 ec e3 22 14 5b 3f d2 e1 2d 63 b0 1f 76 86 | b1 63 72 6a fb 4e 82 bf 51 35 dd 6d 40 d0 0c fe | 67 8d 72 12 35 e5 37 56 4b ff 87 c6 7e 11 c9 78 | 6e c5 6f 6c 57 15 e6 46 9f 3b db 9a 0a e6 67 54 | 5e 67 b1 f8 70 f8 32 93 74 47 8b 02 41 7e 77 f5 | 5b 54 aa 81 67 59 9e e6 5f e5 ef 8a e1 71 c1 0e | 1a b2 2f e3 67 32 4f 50 25 23 97 d9 58 d9 09 de | 8b eb ea 8b 8c 86 bb 09 1e f4 41 c4 ae 61 34 94 | 80 a0 67 ca 3d fc a4 e2 5a 38 cb 99 fd 11 f3 e7 | 2d ca df 3a d2 17 31 9f bf b3 69 51 cd 88 4d 97 | be a4 b6 eb 3f 82 b8 ec ae ae 7a ae 0e 61 3c d8 | 0d 94 22 90 85 2e 7d 86 24 5a 28 18 12 f7 42 c2 | 6b f5 4f 52 da 9c c3 83 fc e7 bb df 9e 23 da a1 | e4 23 72 4d 3e 66 a7 61 3d 7e 0d 3d e0 05 f7 69 | f4 42 7c d0 4f f4 01 1f 49 ae 00 bb 9d 04 82 1c | ef 12 4f 5a 85 b4 55 ac db 79 0c 9a d2 a6 a1 fc | b2 46 f8 75 6b dc c6 d0 dd a8 ee a5 cc 21 e0 f9 | d7 89 e7 38 e0 e0 70 22 f7 2d ce 99 25 4f ce 61 | e2 12 65 39 2d a7 11 f7 5c a8 12 85 ea 05 00 d5 | 53 44 68 fe 5d dd 38 ce ee a5 c4 0f 3f 1a 15 04 | fc 5f bd 9f c6 d5 50 e5 51 0b 8a 68 55 19 31 37 | 81 f4 7c fe 3a 0a fd 87 ae 06 66 1c fc 71 7e 1b | c7 71 ba ad 9b 0c 18 00 37 4b 27 61 41 3b 2c e7 | 4c e4 b3 2a 55 70 cc f5 cc 99 59 26 4d e5 d0 ee | f6 a3 71 6c 07 c1 80 8b 89 d6 6f 1b f0 b0 2b 15 | 50 20 02 27 36 bf 47 ec 3e 61 c2 34 50 d4 92 69 | 9f 9e d5 55 67 5e 41 31 e8 f1 65 a0 27 f9 96 02 | e1 c6 c1 c1 dc ad 87 2e 0c 44 2c 8c 99 2a e5 7d | e6 a4 b2 fe 81 a1 d8 6d 37 75 d1 20 47 fb 3b 3f | 73 09 5f 95 d4 c9 0d 1d 2b f5 47 f5 bf 35 00 e6 | a0 0a 56 98 8c 1d 77 74 65 ee ed f0 20 07 ab ae | 69 8d 53 c1 6e fe 15 d6 c8 c8 0d 52 de 6d 3b a1 | 1f d6 92 df 23 82 df 94 ce 2e e3 e1 eb 0f 9a 7a | 6f 49 27 5d f9 99 0b 50 55 d3 c2 2a e7 96 9c 6b | ef 30 c0 64 2b c2 03 2a 25 58 28 15 73 92 17 44 | 03 e4 0c 84 00 37 84 20 c7 86 9a 2f a5 da 6d f5 | 36 5b 09 d1 dc 06 94 a7 b4 62 91 43 c4 4f 03 36 | a4 81 87 aa bf d7 3d 00 ef 2d ef 09 de be 50 7c | 3f 01 7e 58 aa 3c 95 6f 3f 0d 2b 6e 1b 59 4b 75 | 09 96 0a be af 20 37 cb 30 9b a5 8a 14 4f 40 7b | 4c cc 2b d6 fc 86 ea 63 55 f8 c2 21 86 74 3a 87 | d0 d0 d1 64 e7 5f 17 ed da 86 d0 5f bc e2 10 8f | 6d 48 41 c6 a3 98 b0 0c 30 95 5b e4 3c 09 20 3c | d3 31 61 25 e9 95 ab b7 fb 51 4c 50 f6 87 51 17 | 68 82 30 9e 84 f6 84 f5 a4 f2 db ce e8 72 65 da | 6c e6 f2 d3 51 be 96 65 06 4f a2 b4 08 00 b1 19 | 53 bc 27 78 4a e2 af f6 64 8e 37 ae 6b bc 45 b7 | cc 36 e0 23 f2 26 40 0b a1 9b 6c 19 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_ID (0x5) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | length: 1884 (0x75c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #5 in MAIN_I3 (find_state_ikev1) | start processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in process_v1_packet() at ikev1.c:1459) | #5 is idle | #5 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x220 opt: 0x20c0 | ***parse ISAKMP Identification Payload: | next payload type: ISAKMP_NEXT_CERT (0x6) | length: 191 (0xbf) | ID type: ID_DER_ASN1_DN (0x9) | DOI specific A: 0 (0x0) | DOI specific B: 0 (0x0) | obj: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | obj: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | obj: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | obj: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | obj: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | obj: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | obj: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 77 65 73 | obj: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | obj: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 65 73 | obj: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 | got payload 0x40 (ISAKMP_NEXT_CERT) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_SIG (0x9) | length: 1265 (0x4f1) | cert encoding: CERT_X509_SIGNATURE (0x4) | got payload 0x200 (ISAKMP_NEXT_SIG) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 388 (0x184) | removing 12 bytes of padding | message 'main_inR3' HASH payload not checked early | DER ASN1 DN: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | DER ASN1 DN: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | DER ASN1 DN: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | DER ASN1 DN: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | DER ASN1 DN: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | DER ASN1 DN: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | DER ASN1 DN: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 77 65 73 | DER ASN1 DN: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | DER ASN1 DN: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 65 73 | DER ASN1 DN: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 "TUNNEL-C" #5: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' | global one-shot timer EVENT_FREE_ROOT_CERTS scheduled in 300 seconds | #5 spent 0.00366 milliseconds in find_and_verify_certs() calling get_root_certs() | checking for known CERT payloads | saving certificate of type 'X509_SIGNATURE' | decoded cert: E=user-west@testing.libreswan.org,CN=west.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #5 spent 0.0464 milliseconds in find_and_verify_certs() calling decode_cert_payloads() | cert_issuer_has_current_crl: looking for a CRL issued by E=testing@libreswan.org,CN=Libreswan test CA for mainca,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #5 spent 0.0894 milliseconds in find_and_verify_certs() calling crl_update_check() | missing or expired CRL | crl_strict: 0, ocsp: 0, ocsp_strict: 0, ocsp_post: 0 | verify_end_cert trying profile IPsec | certificate is valid (profile IPsec) | #5 spent 0.0781 milliseconds in find_and_verify_certs() calling verify_end_cert() "TUNNEL-C" #5: certificate verified OK: E=user-west@testing.libreswan.org,CN=west.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b842148 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b823cc8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b81e858 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b8220f8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x56546b8265c8 | unreference key: 0x56546b82f368 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 1-- | #5 spent 0.201 milliseconds in decode_certs() calling add_pubkey_from_nss_cert() | #5 spent 0.441 milliseconds in decode_certs() | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' needs further ID comparison against 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' matched our ID | SAN ID matched, updating that.cert | X509: CERT and ID matches current connection | required RSA CA is '%any' | checking RSA keyid 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' for match with 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | key issuer CA is 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | an RSA Sig check passed with *AwEAAZd0v [remote certificates] | #5 spent 0.127 milliseconds in try_all_RSA_keys() trying a pubkey "TUNNEL-C" #5: Authenticated using RSA | FOR_EACH_CONNECTION_... in ISAKMP_SA_established | complete v1 state transition with STF_OK | [RE]START processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in complete_v1_state_transition() at ikev1.c:2673) | #5 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_MAIN_I3 to state STATE_MAIN_I4 | parent state #5: MAIN_I3(open IKE SA) => MAIN_I4(established IKE SA) | event_already_set, deleting event | state #5 requesting EVENT_RETRANSMIT to be deleted | #5 STATE_MAIN_I4: retransmits: cleared | libevent_free: release ptr-libevent@0x56546b81ed58 | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f8630002b78 | !event_already_set at reschedule | event_schedule: new EVENT_SA_REPLACE-pe@0x7f8630002b78 | inserting event EVENT_SA_REPLACE, timeout in 57 seconds for #5 | libevent_malloc: new ptr-libevent@0x7f864000bcf8 size 128 | pstats #5 ikev1.isakmp established "TUNNEL-C" #5: STATE_MAIN_I4: ISAKMP SA established {auth=RSA_SIG cipher=AES_CBC_256 integ=HMAC_SHA2_256 group=MODP2048} | DPD: dpd_init() called on ISAKMP SA | DPD: Peer supports Dead Peer Detection | DPD: not initializing DPD because DPD is disabled locally | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | unpending state #5 | #5 spent 0.744 milliseconds in process_packet_tail() | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.972 milliseconds in comm_handle_cb() reading and processing packet | processing global timer EVENT_NAT_T_KEEPALIVE | FOR_EACH_STATE_... in nat_traversal_ka_event (for_each_state) | start processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-C | stop processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in for_each_state() at state.c:1577) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-C | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.45:500 (state=#4) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #4) | ff | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-B | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.45:500 (state=#3) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #3) | ff | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-A | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.45:500 (state=#2) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #2) | ff | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-C | stop processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in for_each_state() at state.c:1577) | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | spent 0.14 milliseconds in global timer EVENT_NAT_T_KEEPALIVE | spent 0.00173 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.45:500 | spent 0.00721 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00115 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.45:500 | spent 0.00494 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00159 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.45:500 | spent 0.00538 milliseconds in comm_handle_cb() reading and processing packet | timer_event_cb: processing event@0x56546b7ba938 | handling event EVENT_SA_EXPIRE for parent state #1 | start processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in timer_event_cb() at timer.c:250) | picked newest_isakmp_sa #5 for #1 | IKE SA expired (superseded by #5) | pstats #1 ikev1.isakmp deleted completed | [RE]START processing: state #1 connection "TUNNEL-C" from 192.1.2.45:500 (in delete_state() at state.c:879) "TUNNEL-C" #1: deleting state (STATE_MAIN_R3) aged 60.046s and sending notification | parent state #1: MAIN_R3(established IKE SA) => delete | #1 send IKEv1 delete notification for STATE_MAIN_R3 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 2229872216 (0x84e92658) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'delete msg' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Delete Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 1 (0x1) | SPI size: 16 (0x10) | number of SPIs: 1 (0x1) | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Delete Payload (12:ISAKMP_NEXT_D) | next payload chain: saving location 'ISAKMP Delete Payload'.'next payload type' in 'delete msg' | emitting 8 raw bytes of initiator SPI into ISAKMP Delete Payload | initiator SPI 13 ce 9d 4e da e6 3a 63 | emitting 8 raw bytes of responder SPI into ISAKMP Delete Payload | responder SPI 77 51 4f 24 9b f8 4c 14 | emitting length of ISAKMP Delete Payload: 28 | send delete HASH(1): | 6c 8a 5a b4 0a 71 cb 66 29 ae ff 51 5f 4d ce c9 | a7 6f 79 af 17 98 35 d3 04 86 3e e9 40 35 b0 44 | no IKEv1 message padding required | emitting length of ISAKMP Message: 92 | sending 92 bytes for delete notify through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #1) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 05 01 84 e9 26 58 00 00 00 5c b3 18 ba 44 | 5f 81 00 01 57 1e 25 45 79 23 97 29 b5 91 f3 19 | fc dc bd 5b 96 72 5a 95 67 0c 1d 40 25 3f 92 a9 | f0 53 78 20 cd 67 5c ba ee ba 85 03 23 3d 4a 0e | a1 bc d4 a6 12 76 fc ee 74 78 06 67 | State DB: IKEv1 state not found (flush_incomplete_children) | in connection_discard for connection TUNNEL-C | State DB: deleting IKEv1 state #1 in MAIN_R3 | parent state #1: MAIN_R3(established IKE SA) => UNDEFINED(ignore) | unreference key: 0x56546b81a6a8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 2-- | stop processing: state #1 from 192.1.2.45:500 (in delete_state() at state.c:1143) | unreference key: 0x56546b81a6a8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 1-- | unreference key: 0x56546b822d48 user-west@testing.libreswan.org cnt 1-- | unreference key: 0x56546b82f8d8 @west.testing.libreswan.org cnt 1-- | unreference key: 0x56546b822f98 west@testing.libreswan.org cnt 1-- | unreference key: 0x56546b830308 192.1.2.45 cnt 1-- | libevent_free: release ptr-libevent@0x56546b813de8 | free_event_entry: release EVENT_SA_EXPIRE-pe@0x56546b7ba938 | in statetime_stop() and could not find #1 | processing: STOP state #0 (in timer_event_cb() at timer.c:557) | spent 0.00167 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 92 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 05 01 59 88 21 b1 00 00 00 5c d6 7c 76 92 | 0b f4 1e 8d 52 4c 06 82 62 a8 56 ce d3 ea 35 ff | bc f4 d2 a5 8d cf b9 04 08 3e 57 31 71 b9 ed e8 | 21 88 b2 23 4e c0 1b 9f 4f 47 da 99 0a 55 f0 96 | 35 8e 9e 58 99 6b 00 9c be 9b 1c 50 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 1502093745 (0x598821b1) | length: 92 (0x5c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_INFO (5) | peer and cookies match on #4; msgid=00000000 st_msgid=af958306 st_msgid_phase15=00000000 | peer and cookies match on #3; msgid=00000000 st_msgid=38f90549 st_msgid_phase15=00000000 | peer and cookies match on #2; msgid=00000000 st_msgid=6218486d st_msgid_phase15=00000000 | State DB: IKEv1 state not found (find_v1_info_state) | State DB: IKEv1 state not found (find_state_ikev1_init) | Informational Exchange is for an unknown (expired?) SA with MSGID:0x598821b1 | - unknown SA's md->hdr.isa_ike_initiator_spi.bytes: | 13 ce 9d 4e da e6 3a 63 | - unknown SA's md->hdr.isa_ike_responder_spi.bytes: | 77 51 4f 24 9b f8 4c 14 | stop processing: from 192.1.2.45:500 (in process_md() at demux.c:380) | processing: STOP state #0 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.0502 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00259 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 92 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 08 10 05 01 53 a2 a5 fb 00 00 00 5c a8 42 fb 6e | 82 30 01 4f e8 04 2d 7c c1 9b 7a 6f da 26 60 d6 | a7 3b cf 1a ca 6e b6 26 73 17 e5 d1 34 bc 7b 43 | 69 42 a3 af 11 bc b9 4e 0d e7 5d 4a 31 ea 8b da | 16 13 20 36 c7 28 87 34 8c 71 75 80 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 1403168251 (0x53a2a5fb) | length: 92 (0x5c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_INFO (5) | peer and cookies match on #5; msgid=00000000 st_msgid=00000000 st_msgid_phase15=00000000 | p15 state object #5 found, in STATE_MAIN_I4 | State DB: found IKEv1 state #5 in MAIN_I4 (find_v1_info_state) | start processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in process_v1_packet() at ikev1.c:1479) | #5 is idle | #5 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x100 opt: 0x0 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_D (0xc) | length: 36 (0x24) | got payload 0x1000 (ISAKMP_NEXT_D) needed: 0x0 opt: 0x0 | ***parse ISAKMP Delete Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 16 (0x10) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 3 (0x3) | SPI size: 4 (0x4) | number of SPIs: 1 (0x1) | removing 12 bytes of padding | informational HASH(1): | d9 44 51 87 5b 50 b4 cf 25 94 30 75 63 6a a2 28 | de ec a7 2d ac 73 28 a8 bb 26 23 0c db cc d5 ff | received 'informational' message HASH(1) data ok | parsing 4 raw bytes of ISAKMP Delete Payload into SPI | SPI e9 31 61 bd | FOR_EACH_STATE_... in find_phase2_state_to_delete | start processing: connection "TUNNEL-B" (BACKGROUND) (in accept_delete() at ikev1_main.c:2515) "TUNNEL-C" #5: received Delete SA(0xe93161bd) payload: deleting IPsec State #3 | pstats #3 ikev1.ipsec deleted completed | suspend processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in delete_state() at state.c:879) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.45:500 (in delete_state() at state.c:879) "TUNNEL-B" #3: deleting other state #3 connection (STATE_QUICK_R2) "TUNNEL-B" aged 70.038s and sending notification | child state #3: QUICK_R2(established CHILD SA) => delete | get_sa_info esp.e93161bd@192.1.2.45 | get_sa_info esp.2310b106@192.1.2.23 "TUNNEL-B" #3: ESP traffic information: in=336B out=336B | #3 send IKEv1 delete notification for STATE_QUICK_R2 | FOR_EACH_STATE_... in find_phase1_state | **emit ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 166238581 (0x9e89975) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'delete msg' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Delete Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 3 (0x3) | SPI size: 4 (0x4) | number of SPIs: 1 (0x1) | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Delete Payload (12:ISAKMP_NEXT_D) | next payload chain: saving location 'ISAKMP Delete Payload'.'next payload type' in 'delete msg' | emitting 4 raw bytes of delete payload into ISAKMP Delete Payload | delete payload 23 10 b1 06 | emitting length of ISAKMP Delete Payload: 16 | send delete HASH(1): | 3a 58 da 77 b7 aa 74 b0 4d 51 da 40 b6 88 da 88 | d9 d7 00 f4 08 38 2a 1d 11 17 a7 16 80 9c c8 e7 | emitting 12 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 92 | sending 92 bytes for delete notify through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #5) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 08 10 05 01 09 e8 99 75 00 00 00 5c 55 27 7f f0 | c6 19 ca 76 a2 85 48 d0 af 06 77 8d c9 f8 09 3a | c9 a1 0e 73 b6 57 c1 d6 29 1b 61 f9 1f 64 9a e4 | 3d 6e ce 91 e5 7f 1e 8e 34 33 27 36 2a 76 76 b6 | 42 a6 a7 24 61 42 18 fb 03 3c 07 4f | state #3 requesting EVENT_SA_REPLACE to be deleted | libevent_free: release ptr-libevent@0x7f862c001f78 | free_event_entry: release EVENT_SA_REPLACE-pe@0x7f8640004218 | running updown command "ipsec _updown" for verb down | command executing down-client | executing down-client: PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.244/32' PLUTO_MY_CLIENT_NET='192.0.2.244' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_C | popen cmd is 1324 chars long | cmd( 0):PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_I: | cmd( 80):NTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C: | cmd( 160):=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.lib: | cmd( 240):reswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.244/32' : | cmd( 320):PLUTO_MY_CLIENT_NET='192.0.2.244' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_M: | cmd( 400):Y_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUT: | cmd( 480):O_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=: | cmd( 560):Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.or: | cmd( 640):g' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_: | cmd( 720):PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' P: | cmd( 800):LUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLIC: | cmd( 880):Y='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUT: | cmd( 960):O_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_MY_: | cmd(1040):SOURCEIP='192.0.2.244' PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER: | cmd(1120):_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' P: | cmd(1200):LUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xe9: | cmd(1280):3161bd SPI_OUT=0x2310b106 ipsec _updown 2>&1: | shunt_eroute() called for connection 'TUNNEL-B' to 'replace with shunt' for rt_kind 'prospective erouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-B" is 0xfdfdf | IPsec Sa SPD priority set to 1040351 | delete esp.e93161bd@192.1.2.45 | netlink response for Del SA esp.e93161bd@192.1.2.45 included non-error error | priority calculation of connection "TUNNEL-B" is 0xfdfdf | delete inbound eroute 192.0.1.254/32:0 --0-> 192.0.2.244/32:0 => unk255.10000@192.1.2.23 (raw_eroute) | raw_eroute result=success | delete esp.2310b106@192.1.2.23 | netlink response for Del SA esp.2310b106@192.1.2.23 included non-error error | stop processing: connection "TUNNEL-B" (BACKGROUND) (in update_state_connection() at connections.c:4076) | start processing: connection NULL (in update_state_connection() at connections.c:4077) | in connection_discard for connection TUNNEL-B | State DB: deleting IKEv1 state #3 in QUICK_R2 | child state #3: QUICK_R2(established CHILD SA) => UNDEFINED(ignore) | stop processing: state #3 from 192.1.2.45:500 (in delete_state() at state.c:1143) | resume processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in delete_state() at state.c:1143) | connection 'TUNNEL-B' -POLICY_UP | Deleting states for connection - not including other IPsec SA's | pass 0 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #5 | state #4 | state #2 | pass 1 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #5 | state #4 | state #2 | processing: STOP connection NULL (in accept_delete() at ikev1_main.c:2556) | processing: STOP connection NULL (in accept_delete() at ikev1_main.c:2559) | del: | in statetime_start() with no state | complete v1 state transition with STF_IGNORE | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 1.19 milliseconds in comm_handle_cb() reading and processing packet | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00503 milliseconds in signal handler PLUTO_SIGCHLD | spent 0.0025 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 92 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 08 10 05 01 1c 5c 3c 32 00 00 00 5c 68 6e 66 1b | db b6 08 72 89 51 54 f5 d8 e8 af d0 ab 73 cd 58 | 80 36 a8 6c 0a 83 12 eb fe 05 44 58 6a b2 7b e1 | ce 12 65 93 40 68 80 96 9f fb 3e e2 a9 8e 2b dc | bd b1 57 bb 8e 85 5e d3 27 64 53 ff | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 475806770 (0x1c5c3c32) | length: 92 (0x5c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_INFO (5) | peer and cookies match on #5; msgid=00000000 st_msgid=00000000 st_msgid_phase15=00000000 | p15 state object #5 found, in STATE_MAIN_I4 | State DB: found IKEv1 state #5 in MAIN_I4 (find_v1_info_state) | start processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in process_v1_packet() at ikev1.c:1479) | #5 is idle | #5 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x100 opt: 0x0 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_D (0xc) | length: 36 (0x24) | got payload 0x1000 (ISAKMP_NEXT_D) needed: 0x0 opt: 0x0 | ***parse ISAKMP Delete Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 28 (0x1c) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 1 (0x1) | SPI size: 16 (0x10) | number of SPIs: 1 (0x1) | informational HASH(1): | a9 91 02 f8 52 75 01 68 e5 82 61 e9 21 f2 4b 24 | c8 d8 c7 3c 3f cc 25 ee 40 1c 6e e9 90 de 1d 4d | received 'informational' message HASH(1) data ok | parsing 8 raw bytes of ISAKMP Delete Payload into iCookie | iCookie 7a 3e ee d8 64 fe 14 54 | parsing 8 raw bytes of ISAKMP Delete Payload into rCookie | rCookie d3 7b 19 72 3b a4 45 7b | State DB: found IKEv1 state #5 in MAIN_I4 (find_state_ikev1) | del: "TUNNEL-C" #5: received Delete SA payload: self-deleting ISAKMP State #5 | pstats #5 ikev1.isakmp deleted completed | [RE]START processing: state #5 connection "TUNNEL-C" from 192.1.2.45 (in delete_state() at state.c:879) "TUNNEL-C" #5: deleting state (STATE_MAIN_I4) aged 11.194s and sending notification | parent state #5: MAIN_I4(established IKE SA) => delete | #5 send IKEv1 delete notification for STATE_MAIN_I4 | **emit ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 3083462309 (0xb7c9e6a5) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'delete msg' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Delete Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 1 (0x1) | SPI size: 16 (0x10) | number of SPIs: 1 (0x1) | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Delete Payload (12:ISAKMP_NEXT_D) | next payload chain: saving location 'ISAKMP Delete Payload'.'next payload type' in 'delete msg' | emitting 8 raw bytes of initiator SPI into ISAKMP Delete Payload | initiator SPI 7a 3e ee d8 64 fe 14 54 | emitting 8 raw bytes of responder SPI into ISAKMP Delete Payload | responder SPI d3 7b 19 72 3b a4 45 7b | emitting length of ISAKMP Delete Payload: 28 | send delete HASH(1): | 76 a2 29 50 9e bb cc 27 e4 78 f7 8d c3 54 85 70 | c2 c5 e6 70 8c b4 d2 23 fb 5a a7 eb 51 ad 55 d3 | no IKEv1 message padding required | emitting length of ISAKMP Message: 92 | sending 92 bytes for delete notify through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #5) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 08 10 05 01 b7 c9 e6 a5 00 00 00 5c 45 1b 48 17 | 44 ee f1 cc 42 26 2f 7d 62 a8 50 7b 76 9e 6f 26 | fe 2b 2d e3 47 87 83 bc 80 79 0f f0 38 be 60 c7 | 1b 70 d9 75 e4 bd 08 24 f5 9f fc 2b 6c a8 34 ee | f5 1c 07 4d 7b 2f 19 21 60 ed 30 a2 | state #5 requesting EVENT_SA_REPLACE to be deleted | libevent_free: release ptr-libevent@0x7f864000bcf8 | free_event_entry: release EVENT_SA_REPLACE-pe@0x7f8630002b78 | State DB: IKEv1 state not found (flush_incomplete_children) | in connection_discard for connection TUNNEL-C | State DB: deleting IKEv1 state #5 in MAIN_I4 | parent state #5: MAIN_I4(established IKE SA) => UNDEFINED(ignore) | unreference key: 0x56546b8261e8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 2-- | stop processing: state #5 from 192.1.2.45 (in delete_state() at state.c:1143) | unreference key: 0x56546b8261e8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 1-- | unreference key: 0x56546b8463d8 user-west@testing.libreswan.org cnt 1-- | unreference key: 0x56546b8432d8 @west.testing.libreswan.org cnt 1-- | unreference key: 0x56546b842198 west@testing.libreswan.org cnt 1-- | unreference key: 0x56546b826668 192.1.2.45 cnt 1-- | in statetime_start() with no state | complete v1 state transition with STF_IGNORE | stop processing: from 192.1.2.45:500 (in process_md() at demux.c:380) | processing: STOP state #0 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.51 milliseconds in comm_handle_cb() reading and processing packet | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_STATE_... in show_states_status (sort_states) | FOR_EACH_STATE_... in sort_states | get_sa_info esp.ac88167e@192.1.2.23 | get_sa_info esp.f384cffa@192.1.2.45 | get_sa_info esp.58b85bc4@192.1.2.23 | get_sa_info esp.2605d62c@192.1.2.45 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 1.09 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) shutting down | processing: RESET whack log_fd (was fd@16) (in exit_pluto() at plutomain.c:1825) destroying root certificate cache | certs and keys locked by 'free_preshared_secrets' forgetting secrets | certs and keys unlocked by 'free_preshared_secrets' | unreference key: 0x56546b81a188 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | unreference key: 0x56546b819bf8 user-east@testing.libreswan.org cnt 1-- | unreference key: 0x56546b818828 @east.testing.libreswan.org cnt 1-- | unreference key: 0x56546b818168 east@testing.libreswan.org cnt 1-- | unreference key: 0x56546b81b1e8 192.1.2.23 cnt 1-- | start processing: connection "TUNNEL-C" (in delete_connection() at connections.c:189) | Deleting states for connection - including all other IPsec SA's of this IKE SA | pass 0 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #4 | suspend processing: connection "TUNNEL-C" (in foreach_state_by_connection_func_delete() at state.c:1310) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in foreach_state_by_connection_func_delete() at state.c:1310) | pstats #4 ikev1.ipsec deleted completed | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.45:500 (in delete_state() at state.c:879) "TUNNEL-C" #4: deleting state (STATE_QUICK_R2) aged 71.486s and sending notification | child state #4: QUICK_R2(established CHILD SA) => delete | get_sa_info esp.2605d62c@192.1.2.45 | get_sa_info esp.58b85bc4@192.1.2.23 "TUNNEL-C" #4: ESP traffic information: in=336B out=336B | #4 send IKEv1 delete notification for STATE_QUICK_R2 | FOR_EACH_STATE_... in find_phase1_state | no Phase 1 state for Delete | state #4 requesting EVENT_SA_REPLACE to be deleted | libevent_free: release ptr-libevent@0x7f86440027d8 | free_event_entry: release EVENT_SA_REPLACE-pe@0x7f8638002b78 | running updown command "ipsec _updown" for verb down | command executing down-client | executing down-client: PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.234/32' PLUTO_MY_CLIENT_NET='192.0.2.234' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_C | popen cmd is 1324 chars long | cmd( 0):PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_I: | cmd( 80):NTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C: | cmd( 160):=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.lib: | cmd( 240):reswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.234/32' : | cmd( 320):PLUTO_MY_CLIENT_NET='192.0.2.234' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_M: | cmd( 400):Y_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLUT: | cmd( 480):O_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=: | cmd( 560):Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.or: | cmd( 640):g' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_: | cmd( 720):PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' P: | cmd( 800):LUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLIC: | cmd( 880):Y='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUT: | cmd( 960):O_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_MY_: | cmd(1040):SOURCEIP='192.0.2.234' PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER: | cmd(1120):_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' P: | cmd(1200):LUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x26: | cmd(1280):05d62c SPI_OUT=0x58b85bc4 ipsec _updown 2>&1: | shunt_eroute() called for connection 'TUNNEL-C' to 'replace with shunt' for rt_kind 'prospective erouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-C" is 0xfdfdf | IPsec Sa SPD priority set to 1040351 | delete esp.2605d62c@192.1.2.45 | netlink response for Del SA esp.2605d62c@192.1.2.45 included non-error error | priority calculation of connection "TUNNEL-C" is 0xfdfdf | delete inbound eroute 192.0.1.254/32:0 --0-> 192.0.2.234/32:0 => unk255.10000@192.1.2.23 (raw_eroute) | raw_eroute result=success | delete esp.58b85bc4@192.1.2.23 | netlink response for Del SA esp.58b85bc4@192.1.2.23 included non-error error | stop processing: connection "TUNNEL-C" (BACKGROUND) (in update_state_connection() at connections.c:4076) | start processing: connection NULL (in update_state_connection() at connections.c:4077) | in connection_discard for connection TUNNEL-C | State DB: deleting IKEv1 state #4 in QUICK_R2 | child state #4: QUICK_R2(established CHILD SA) => UNDEFINED(ignore) | stop processing: state #4 from 192.1.2.45:500 (in delete_state() at state.c:1143) | processing: STOP state #0 (in foreach_state_by_connection_func_delete() at state.c:1312) | state #2 | pass 1 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #2 | shunt_eroute() called for connection 'TUNNEL-C' to 'delete' for rt_kind 'unrouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-C" is 0xfdfdf | priority calculation of connection "TUNNEL-C" is 0xfdfdf | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-C" unrouted: "TUNNEL-A" erouted | flush revival: connection 'TUNNEL-C' wasn't on the list | processing: STOP connection NULL (in discard_connection() at connections.c:249) | start processing: connection "TUNNEL-B" (in delete_connection() at connections.c:189) | Deleting states for connection - including all other IPsec SA's of this IKE SA | pass 0 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #2 | pass 1 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #2 | shunt_eroute() called for connection 'TUNNEL-B' to 'delete' for rt_kind 'unrouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-B" is 0xfdfdf | priority calculation of connection "TUNNEL-B" is 0xfdfdf | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-B" unrouted: "TUNNEL-A" erouted | flush revival: connection 'TUNNEL-B' wasn't on the list | stop processing: connection "TUNNEL-B" (in discard_connection() at connections.c:249) | start processing: connection "TUNNEL-A" (in delete_connection() at connections.c:189) | Deleting states for connection - including all other IPsec SA's of this IKE SA | pass 0 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #2 | suspend processing: connection "TUNNEL-A" (in foreach_state_by_connection_func_delete() at state.c:1310) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in foreach_state_by_connection_func_delete() at state.c:1310) | pstats #2 ikev1.ipsec deleted completed | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.45:500 (in delete_state() at state.c:879) "TUNNEL-A" #2: deleting state (STATE_QUICK_R2) aged 71.709s and sending notification | child state #2: QUICK_R2(established CHILD SA) => delete | get_sa_info esp.f384cffa@192.1.2.45 | get_sa_info esp.ac88167e@192.1.2.23 "TUNNEL-A" #2: ESP traffic information: in=336B out=336B | #2 send IKEv1 delete notification for STATE_QUICK_R2 | FOR_EACH_STATE_... in find_phase1_state | no Phase 1 state for Delete | state #2 requesting EVENT_SA_REPLACE to be deleted | libevent_free: release ptr-libevent@0x7f8634003618 | free_event_entry: release EVENT_SA_REPLACE-pe@0x56546b81fed8 | running updown command "ipsec _updown" for verb down | command executing down-client | executing down-client: PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.254/32' PLUTO_MY_CLIENT_NET='192.0.2.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_C | popen cmd is 1324 chars long | cmd( 0):PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_I: | cmd( 80):NTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C: | cmd( 160):=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.lib: | cmd( 240):reswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.254/32' : | cmd( 320):PLUTO_MY_CLIENT_NET='192.0.2.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_M: | cmd( 400):Y_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUT: | cmd( 480):O_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=: | cmd( 560):Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.or: | cmd( 640):g' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_: | cmd( 720):PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' P: | cmd( 800):LUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLIC: | cmd( 880):Y='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUT: | cmd( 960):O_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_MY_: | cmd(1040):SOURCEIP='192.0.2.254' PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER: | cmd(1120):_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' P: | cmd(1200):LUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xf3: | cmd(1280):84cffa SPI_OUT=0xac88167e ipsec _updown 2>&1: | shunt_eroute() called for connection 'TUNNEL-A' to 'replace with shunt' for rt_kind 'prospective erouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-A" is 0xfdfdf | IPsec Sa SPD priority set to 1040351 | delete esp.f384cffa@192.1.2.45 | netlink response for Del SA esp.f384cffa@192.1.2.45 included non-error error | priority calculation of connection "TUNNEL-A" is 0xfdfdf | delete inbound eroute 192.0.1.254/32:0 --0-> 192.0.2.254/32:0 => unk255.10000@192.1.2.23 (raw_eroute) | raw_eroute result=success | delete esp.ac88167e@192.1.2.23 | netlink response for Del SA esp.ac88167e@192.1.2.23 included non-error error | stop processing: connection "TUNNEL-A" (BACKGROUND) (in update_state_connection() at connections.c:4076) | start processing: connection NULL (in update_state_connection() at connections.c:4077) | in connection_discard for connection TUNNEL-A | State DB: deleting IKEv1 state #2 in QUICK_R2 | child state #2: QUICK_R2(established CHILD SA) => UNDEFINED(ignore) | stop processing: state #2 from 192.1.2.45:500 (in delete_state() at state.c:1143) | processing: STOP state #0 (in foreach_state_by_connection_func_delete() at state.c:1312) | pass 1 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | shunt_eroute() called for connection 'TUNNEL-A' to 'delete' for rt_kind 'unrouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-A" is 0xfdfdf | priority calculation of connection "TUNNEL-A" is 0xfdfdf | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-A" unrouted: NULL | running updown command "ipsec _updown" for verb unroute | command executing unroute-client | executing unroute-client: PLUTO_VERB='unroute-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.254/32' PLUTO_MY_CLIENT_NET='192.0.2.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='none' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CON | popen cmd is 1305 chars long | cmd( 0):PLUTO_VERB='unroute-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUT: | cmd( 80):O_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID: | cmd( 160):='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.: | cmd( 240):libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.2.254/3: | cmd( 320):2' PLUTO_MY_CLIENT_NET='192.0.2.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUT: | cmd( 400):O_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='none' : | cmd( 480):PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan,: | cmd( 560): OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswa: | cmd( 640):n.org' PLUTO_PEER_CLIENT='192.0.1.254/32' PLUTO_PEER_CLIENT_NET='192.0.1.254' PL: | cmd( 720):UTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL=': | cmd( 800):0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RS: | cmd( 880):ASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CON: | cmd( 960):N_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_MY_SOURC: | cmd(1040):EIP='192.0.2.254' PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMA: | cmd(1120):IN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_: | cmd(1200):NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x0 SPI_O: | cmd(1280):UT=0x0 ipsec _updown 2>&1: unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. | free hp@0x56546b818428 | flush revival: connection 'TUNNEL-A' wasn't on the list | processing: STOP connection NULL (in discard_connection() at connections.c:249) | crl fetch request list locked by 'free_crl_fetch' | crl fetch request list unlocked by 'free_crl_fetch' shutting down interface lo/lo 127.0.0.1:4500 shutting down interface lo/lo 127.0.0.1:500 shutting down interface eth0/eth0 192.0.2.254:4500 shutting down interface eth0/eth0 192.0.2.254:500 shutting down interface eth0:1/eth0:1 192.0.2.244:4500 shutting down interface eth0:1/eth0:1 192.0.2.244:500 shutting down interface eth0:2/eth0:2 192.0.2.234:4500 shutting down interface eth0:2/eth0:2 192.0.2.234:500 shutting down interface eth1/eth1 192.1.2.23:4500 shutting down interface eth1/eth1 192.1.2.23:500 | FOR_EACH_STATE_... in delete_states_dead_interfaces | libevent_free: release ptr-libevent@0x56546b8066b8 | free_event_entry: release EVENT_NULL-pe@0x56546b812648 | libevent_free: release ptr-libevent@0x56546b7acd38 | free_event_entry: release EVENT_NULL-pe@0x56546b8126f8 | libevent_free: release ptr-libevent@0x56546b7ac688 | free_event_entry: release EVENT_NULL-pe@0x56546b8127a8 | libevent_free: release ptr-libevent@0x56546b7abf58 | free_event_entry: release EVENT_NULL-pe@0x56546b812858 | libevent_free: release ptr-libevent@0x56546b7ac058 | free_event_entry: release EVENT_NULL-pe@0x56546b812908 | libevent_free: release ptr-libevent@0x56546b7ac108 | free_event_entry: release EVENT_NULL-pe@0x56546b812f78 | libevent_free: release ptr-libevent@0x56546b813098 | free_event_entry: release EVENT_NULL-pe@0x56546b813028 | libevent_free: release ptr-libevent@0x56546b8131f8 | free_event_entry: release EVENT_NULL-pe@0x56546b813188 | libevent_free: release ptr-libevent@0x56546b813358 | free_event_entry: release EVENT_NULL-pe@0x56546b8132e8 | libevent_free: release ptr-libevent@0x56546b8134b8 | free_event_entry: release EVENT_NULL-pe@0x56546b813448 | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | libevent_free: release ptr-libevent@0x56546b806768 | free_event_entry: release EVENT_NULL-pe@0x56546b7fa908 | libevent_free: release ptr-libevent@0x56546b7acc88 | free_event_entry: release EVENT_NULL-pe@0x56546b7fa468 | libevent_free: release ptr-libevent@0x56546b7f3468 | free_event_entry: release EVENT_NULL-pe@0x56546b7b43e8 | global timer EVENT_REINIT_SECRET uninitialized | global timer EVENT_SHUNT_SCAN uninitialized | global timer EVENT_PENDING_DDNS uninitialized | global timer EVENT_PENDING_PHASE2 uninitialized | global timer EVENT_CHECK_CRLS uninitialized | global timer EVENT_REVIVE_CONNS uninitialized | global timer EVENT_FREE_ROOT_CERTS uninitialized | global timer EVENT_RESET_LOG_RATE_LIMIT uninitialized | global timer EVENT_NAT_T_KEEPALIVE uninitialized | libevent_free: release ptr-libevent@0x56546b7b89a8 | signal event handler PLUTO_SIGCHLD uninstalled | libevent_free: release ptr-libevent@0x56546b72df08 | signal event handler PLUTO_SIGTERM uninstalled | libevent_free: release ptr-libevent@0x56546b726618 | signal event handler PLUTO_SIGHUP uninstalled | libevent_free: release ptr-libevent@0x56546b7266e8 | signal event handler PLUTO_SIGSYS uninstalled | releasing event base | libevent_free: release ptr-libevent@0x56546b811dc8 | libevent_free: release ptr-libevent@0x56546b7f4d28 | libevent_free: release ptr-libevent@0x56546b7f4cd8 | libevent_free: release ptr-libevent@0x56546b813ef8 | libevent_free: release ptr-libevent@0x56546b7f4c98 | libevent_free: release ptr-libevent@0x56546b811a58 | libevent_free: release ptr-libevent@0x56546b811cc8 | libevent_free: release ptr-libevent@0x56546b7f4ed8 | libevent_free: release ptr-libevent@0x56546b7fa4d8 | libevent_free: release ptr-libevent@0x56546b7fa138 | libevent_free: release ptr-libevent@0x56546b813568 | libevent_free: release ptr-libevent@0x56546b813408 | libevent_free: release ptr-libevent@0x56546b8132a8 | libevent_free: release ptr-libevent@0x56546b813148 | libevent_free: release ptr-libevent@0x56546b812fe8 | libevent_free: release ptr-libevent@0x56546b812f38 | libevent_free: release ptr-libevent@0x56546b8128c8 | libevent_free: release ptr-libevent@0x56546b812818 | libevent_free: release ptr-libevent@0x56546b812768 | libevent_free: release ptr-libevent@0x56546b8126b8 | libevent_free: release ptr-libevent@0x56546b72d038 | libevent_free: release ptr-libevent@0x56546b811d48 | libevent_free: release ptr-libevent@0x56546b811d08 | libevent_free: release ptr-libevent@0x56546b811bc8 | libevent_free: release ptr-libevent@0x56546b811d88 | libevent_free: release ptr-libevent@0x56546b811a98 | libevent_free: release ptr-libevent@0x56546b7ba538 | libevent_free: release ptr-libevent@0x56546b7ba4b8 | libevent_free: release ptr-libevent@0x56546b72d3a8 | releasing global libevent data | libevent_free: release ptr-libevent@0x56546b7ba6b8 | libevent_free: release ptr-libevent@0x56546b7ba638 | libevent_free: release ptr-libevent@0x56546b7ba5b8 leak detective found no leaks